CONTAGIOUS INTERVIEW CAMPAIGN ACTIVITY

2026-02-04 Paloalto Networks

https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-02-04-IOCs-for-December-2025-Contagious-Interview-activity.txt

Thumbnail for CONTAGIOUS INTERVIEW CAMPAIGN ACTIVITY

Unit 42 reports that North Korean actors continued Contagious Interview activity into December 2025, using fake recruiter personas against people seeking crypto and technology jobs. The campaign lures targets to attacker-created GitHub repositories during recruitment interactions, using the repositories to host malware. The reported objective is deployment of the InvisibleFerret Python backdoor, which supports remote code execution, keylogging, and cryptocurrency wallet theft. The excerpt lists associated file hashes, IP addresses 67.203.7[.]205 and 45.43.11[.]199, and a GitHub repository that was active in mid-December 2025 before being taken offline. The activity matters because it shows ongoing DPRK use of social engineering and developer-platform abuse to reach job seekers in high-value crypto and tech environments.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 67.203.7.205 2026-01-21 2026-02-26
HASH 8c63faeb6cdf21d981d9f424dd599a4… 2026-02-04 2026-02-04
HASH a31325d140903e8be2217b56756c449… 2026-02-04 2026-02-04
HASH a04d5e05fdd89099a7c1759c679fcf2… 2026-02-04 2026-02-04
HASH 7bd7c41bc5b91cced6630cfc64c595e… 2026-02-04 2026-02-04
HASH 17eeae8ac77d6b866651356b60646f0… 2026-02-04 2026-02-04
IPv4 45.43.11.199 2026-01-12 2026-02-04

Related Actors

Related Reports

« Back