CONTAGIOUS INTERVIEW CAMPAIGN ACTIVITY
2026-02-04 • Paloalto Networks •
Unit 42 reports that North Korean actors continued Contagious Interview activity into December 2025, using fake recruiter personas against people seeking crypto and technology jobs. The campaign lures targets to attacker-created GitHub repositories during recruitment interactions, using the repositories to host malware. The reported objective is deployment of the InvisibleFerret Python backdoor, which supports remote code execution, keylogging, and cryptocurrency wallet theft. The excerpt lists associated file hashes, IP addresses 67.203.7[.]205 and 45.43.11[.]199, and a GitHub repository that was active in mid-December 2025 before being taken offline. The activity matters because it shows ongoing DPRK use of social engineering and developer-platform abuse to reach job seekers in high-value crypto and tech environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 67.203.7.205 | 2026-01-21 | 2026-02-26 |
| HASH | 8c63faeb6cdf21d981d9f424dd599a4… | 2026-02-04 | 2026-02-04 |
| HASH | a31325d140903e8be2217b56756c449… | 2026-02-04 | 2026-02-04 |
| HASH | a04d5e05fdd89099a7c1759c679fcf2… | 2026-02-04 | 2026-02-04 |
| HASH | 7bd7c41bc5b91cced6630cfc64c595e… | 2026-02-04 | 2026-02-04 |
| HASH | 17eeae8ac77d6b866651356b60646f0… | 2026-02-04 | 2026-02-04 |
| IPv4 | 45.43.11.199 | 2026-01-12 | 2026-02-04 |