More active DPRK macOS malware "Contagious Interview"

2025-11-23 L0Psec

https://archive.md/GuCHv

Thumbnail for More active DPRK macOS malware "Contagious Interview"

A DPRK Contagious Interview macOS lure used an “Algorand Hiring Assessment” theme to push a ClickFix-style prompt that told victims to update FFmpeg macOS drivers. The prompt led to execution of a script from /var/tmp that selected an ARM or Intel release ZIP, unpacked files under /var/tmp/CDrivers, and set LaunchAgent persistence through drivfixer.sh running a Go backdoor. The Swift app bundle, named MediaPatcher, used Dropbox and NSAlerts to capture the user’s password, while the backdoor and stealer code included browser and Chrome extension collection behavior. Reported IOCs include levinpros.com, patch.levinpros.com, C2 95.169.180.140:8080, and hashes for drivfixer.sh, the app, and a related script.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.169.180.140 2025-11-23 2026-03-23
HASH 694447b18338e6dc074603a1a149e4e… 2025-11-23 2025-11-23
HASH 9610cf0bf17bf143f6bfef9850e4a61… 2025-11-23 2025-11-23
HASH 0048b92365f3ab21540b20a00a306c2… 2025-11-23 2025-11-23
URL https://levinpros\.com/join/ljv… 2025-11-23 2025-11-23
URL https://levinpros.com/join/ljvt… 2025-11-23 2025-11-23
DOMAIN levinpros.com 2025-11-23 2025-11-23

Related Actors

Related Reports

« Back