DPRK Contagious Interview Lure - Go Backdoor & Swift App
2025-11-23 • L0Psec •
The video examines a newly observed DPRK Contagious Interview lure targeting job seekers, primarily in the cryptocurrency sector. The lure uses a related Swift application and leads victims to download a ZIP archive containing a Golang backdoor. The author notes that the Swift app resembles a sample they previously reverse engineered and that a related X/Twitter thread contains IOCs. The activity is relevant to DPRK tracking because it aligns with the long-running fake-recruitment tradecraft used to compromise job seekers and cryptocurrency-adjacent targets.
Related Actors
Related Reports
2025-11-23 •
70% Match
#ContagiousInterview
Shares tag: ContagiousInterview • Same author: L0Psec • Published within a week
2025-10-21 •
70% Match
Fake Jobs, Real Malware. Uncovering How Cybercriminals are Exploiting the Employment Market
Bitdefender
Shares tags: Youtube, ContagiousInterview
Shares tag: ContagiousInterview • Published within a month
2025-12-10 •
60% Match
#ContagiousInterview
Shares tag: ContagiousInterview • Published within a month
Shares tag: ContagiousInterview • Published within a week
2025-11-26 •
60% Match
#NPM
#ContagiousInterview
#OtterCookie
#T1082
#T1119
#T1005
#T1587.001
#T1041
#T1113
#T1608.001
#T1195.002
#T1115
#T1083
#T1497
#T1056.001
#T1059.007
#T1036
#T1204.002
#T1555.003
#T1583.006
#T1547.001
#T1539
#T1583.001
#T1656
#T1105
#T1204.005
#T1571
#T1657
#T1587
#T1585
#T1555.001
#T1546.016
#T1217
Shares tag: ContagiousInterview • Published within a week