Lazarus의 Contagious Interview 캠페인 변종 분석

2025-01-20 ENKI Analysis of Variants in the Lazarus Contagious Interview Campaign

https://www.enki.co.kr/media-center/blog/analysis-of-variants-in-lazarus-s-contagious-interview-campaign

Thumbnail for Lazarus의 Contagious Interview 캠페인 변종 분석

ENKI tracks a Lazarus-attributed Contagious Interview variant that continues to target job seekers through fake recruitment activity with an apparent cryptocurrency-theft objective. The newer flow replaces coding-test package lures with a fake Willo-style video interview site that claims camera access is blocked and instructs victims to run curl commands for Windows or macOS. Windows victims receive VBS and JavaScript stages that download NVIDIA-themed archives, establish persistence, and compile a Go backdoor from source, while macOS victims run shell scripts, install a LaunchAgent, execute a Go backdoor, and may see a fake Chrome prompt used to steal the user password. The backdoor contacts hardcoded C2 infrastructure over HTTP POST, encrypts messages with RC4, sends host and OS details, and supports command execution based on decoded message types. The campaign shows Lazarus adapting social-engineering prompts, cross-platform delivery, persistence, and C2 tradecraft within Contagious Interview activity.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.jz-aws.info 2025-01-05 2025-08-28
HASH bfac94bfb53b4c0ac346706b0629635… 2025-01-20 2025-08-25
DOMAIN api.camera-drive.org 2025-01-20 2025-08-25
IPv4 216.74.123.191 2025-01-05 2025-08-25
HASH b2a4a981ba7cc2add74737957efdfcb… 2025-01-20 2025-02-13
DOMAIN digitpotalent.com 2025-01-20 2025-02-13
DOMAIN digitptalent.com 2025-01-20 2025-02-13
HASH 13e7589c778b4b36420ce77145a98b7… 2025-01-20 2025-01-20
HASH b3da2af06b5828d6809614c4c86a5df… 2025-01-20 2025-01-20
HASH cee03de4bd70cbd7b6bca498d3cf9c6… 2025-01-20 2025-01-20
HASH c56a1897e97a5e52bf1d879eba55541… 2025-01-20 2025-01-20
HASH 35f27685fbd1b0507106862870bafa5… 2025-01-20 2025-01-20
HASH a01ebbcc2aa25527ea4a0367c00c780… 2025-01-20 2025-01-20
HASH bab567e14eedf6690fbee8ac4ac448a… 2025-01-20 2025-01-20
HASH 10e4c74df854f63951facfd589717be… 2025-01-20 2025-01-20
HASH b951066189461d2acd27b635f3f858b… 2025-01-20 2025-01-20
HASH 98373befd5fd24ebac29604848e15b3… 2025-01-20 2025-01-20
URL https://api.camera-drive.org/nv… 2025-01-20 2025-01-20
URL https://api.camera-drive.org/nv… 2025-01-20 2025-01-20
URL https://api.camera-drive.org/ff… 2025-01-20 2025-01-20
URL https://api.camera-drive.org/VC… 2025-01-20 2025-01-20
URL https://api.camera-drive.org/VC… 2025-01-20 2025-01-20
URL https://api.jz-aws.info/public/… 2025-01-05 2025-01-20

Related Actors

Related Reports

« Back