Lazarus의 Contagious Interview 캠페인 변종 분석
2025-01-20 • ENKI • Analysis of Variants in the Lazarus Contagious Interview Campaign •
ENKI tracks a Lazarus-attributed Contagious Interview variant that continues to target job seekers through fake recruitment activity with an apparent cryptocurrency-theft objective. The newer flow replaces coding-test package lures with a fake Willo-style video interview site that claims camera access is blocked and instructs victims to run curl commands for Windows or macOS. Windows victims receive VBS and JavaScript stages that download NVIDIA-themed archives, establish persistence, and compile a Go backdoor from source, while macOS victims run shell scripts, install a LaunchAgent, execute a Go backdoor, and may see a fake Chrome prompt used to steal the user password. The backdoor contacts hardcoded C2 infrastructure over HTTP POST, encrypts messages with RC4, sends host and OS details, and supports command execution based on decoded message types. The campaign shows Lazarus adapting social-engineering prompts, cross-platform delivery, persistence, and C2 tradecraft within Contagious Interview activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.jz-aws.info | 2025-01-05 | 2025-08-28 |
| HASH | bfac94bfb53b4c0ac346706b0629635… | 2025-01-20 | 2025-08-25 |
| DOMAIN | api.camera-drive.org | 2025-01-20 | 2025-08-25 |
| IPv4 | 216.74.123.191 | 2025-01-05 | 2025-08-25 |
| HASH | b2a4a981ba7cc2add74737957efdfcb… | 2025-01-20 | 2025-02-13 |
| DOMAIN | digitpotalent.com | 2025-01-20 | 2025-02-13 |
| DOMAIN | digitptalent.com | 2025-01-20 | 2025-02-13 |
| HASH | 13e7589c778b4b36420ce77145a98b7… | 2025-01-20 | 2025-01-20 |
| HASH | b3da2af06b5828d6809614c4c86a5df… | 2025-01-20 | 2025-01-20 |
| HASH | cee03de4bd70cbd7b6bca498d3cf9c6… | 2025-01-20 | 2025-01-20 |
| HASH | c56a1897e97a5e52bf1d879eba55541… | 2025-01-20 | 2025-01-20 |
| HASH | 35f27685fbd1b0507106862870bafa5… | 2025-01-20 | 2025-01-20 |
| HASH | a01ebbcc2aa25527ea4a0367c00c780… | 2025-01-20 | 2025-01-20 |
| HASH | bab567e14eedf6690fbee8ac4ac448a… | 2025-01-20 | 2025-01-20 |
| HASH | 10e4c74df854f63951facfd589717be… | 2025-01-20 | 2025-01-20 |
| HASH | b951066189461d2acd27b635f3f858b… | 2025-01-20 | 2025-01-20 |
| HASH | 98373befd5fd24ebac29604848e15b3… | 2025-01-20 | 2025-01-20 |
| URL | https://api.camera-drive.org/nv… | 2025-01-20 | 2025-01-20 |
| URL | https://api.camera-drive.org/nv… | 2025-01-20 | 2025-01-20 |
| URL | https://api.camera-drive.org/ff… | 2025-01-20 | 2025-01-20 |
| URL | https://api.camera-drive.org/VC… | 2025-01-20 | 2025-01-20 |
| URL | https://api.camera-drive.org/VC… | 2025-01-20 | 2025-01-20 |
| URL | https://api.jz-aws.info/public/… | 2025-01-05 | 2025-01-20 |