Inside DPRK's Fake Job Platform Targeting U.S. AI Talent
2025-11-20 • Validin •
Validin tracks a DPRK-linked Contagious Interview variant that uses a polished fake hiring platform at lenvny[.]com to target job seekers, including software developers, AI researchers, cryptocurrency professionals, and other technical candidates. The operation differs from DPRK IT-worker impersonation schemes by compromising real applicants through a staged recruiting flow: LinkedIn contact, interview process, video-answer request, ClickFix-style webcam troubleshooting, and malware delivery. The lure is built as a React/Next.js job portal with realistic company pages, UUID-driven job listings, resume upload prompts, social-proof elements, and impersonated AI, crypto, and Web3 brands such as Anthropic, Yuga Labs, Anchorage Digital, and Digital Currency Group. Its completeness and startup-like design language make the malicious workflow look like a normal hiring process, increasing the chance that victims will submit identity details and follow later malware-delivery instructions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.lever.co/ | 2025-11-20 | 2025-11-20 |
| URL | https://app.lenvny.com/cam-v-ab… | 2025-11-20 | 2025-11-20 |
| URL | https://drivers.softpedia.com/d… | 2025-11-20 | 2025-11-20 |
| DOMAIN | carrerlilla.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | app.lenvny.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | drivers.softpedia.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | lenvny.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | assureeval.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | advisorflux.com | 2025-11-20 | 2025-11-20 |
| IPv4 | 72.61.9.45 | 2025-11-20 | 2025-11-20 |
| IPv4 | 69.62.86.78 | 2025-11-20 | 2025-11-20 |