More active DPRK macOS malware "Contagious Interview"
2025-11-23 • L0Psec •
A DPRK Contagious Interview macOS lure used an “Algorand Hiring Assessment” theme to push a ClickFix-style prompt that told victims to update FFmpeg macOS drivers. The prompt led to execution of a script from /var/tmp that selected an ARM or Intel release ZIP, unpacked files under /var/tmp/CDrivers, and set LaunchAgent persistence through drivfixer.sh running a Go backdoor. The Swift app bundle, named MediaPatcher, used Dropbox and NSAlerts to capture the user’s password, while the backdoor and stealer code included browser and Chrome extension collection behavior. Reported IOCs include levinpros.com, patch.levinpros.com, C2 95.169.180.140:8080, and hashes for drivfixer.sh, the app, and a related script.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.169.180.140 | 2025-11-23 | 2026-03-23 |
| HASH | 694447b18338e6dc074603a1a149e4e… | 2025-11-23 | 2025-11-23 |
| HASH | 9610cf0bf17bf143f6bfef9850e4a61… | 2025-11-23 | 2025-11-23 |
| HASH | 0048b92365f3ab21540b20a00a306c2… | 2025-11-23 | 2025-11-23 |
| URL | https://levinpros\.com/join/ljv… | 2025-11-23 | 2025-11-23 |
| URL | https://levinpros.com/join/ljvt… | 2025-11-23 | 2025-11-23 |
| DOMAIN | levinpros.com | 2025-11-23 | 2025-11-23 |