North Korea Tried to Hack Our CEO Through a Fake Job Interview on LinkedIn
2026-03-05 • Allsecure •
A fake LinkedIn recruiter posing as a 0G Labs representative targeted a crypto/Web3 CEO with a technical assessment that required cloning a Bitbucket repository and opening it in VS Code or Cursor. The repository hid three independent execution paths: a VS Code folder-open task that piped a Vercel stager into Node, an npm prepare hook, and route code that exfiltrated process.env secrets before executing server-supplied JavaScript. The captured BeaverTail chain fingerprinted the host, beaconed every five seconds to 104.192.42.117:3000, received a second-stage Node.js bootstrapper, and attempted to run an in-memory C2 agent with hidden child processes, ID rotation, and a kill switch. Operators killed the analysis sessions after recognizing AWS datacenter infrastructure, showing active victim triage tied to the DPRK Contagious Interview campaign.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.ipify.org | 2019-12-11 | 2026-03-17 |
| HASH | 66d991be156e9b602dc0d22c56424a5… | 2026-03-05 | 2026-03-05 |
| HASH | 4f57c2602488c1c72bf4bfbb2c720cd… | 2026-03-05 | 2026-03-05 |
| HASH | 0440af4634fdc23313f008d5341439d… | 2026-03-05 | 2026-03-05 |
| HASH | c913a6b89e6f2d51cb9d6b45f75970c… | 2026-03-05 | 2026-03-05 |
| HASH | 98c5dfa2ad170d221c1110f28b8f129b | 2026-03-05 | 2026-03-05 |
| HASH | 76bb590bdf7dd413232da22466645d3… | 2026-03-05 | 2026-03-05 |
| HASH | 28e73ce85db813ba0839ee077428eaa… | 2026-03-05 | 2026-03-05 |
| HASH | b460480112ee5c5e47baf0a13699b88… | 2026-03-05 | 2026-03-05 |
| HASH | 37eb8e11b40527de0881189064c657f… | 2026-03-05 | 2026-03-05 |
| HASH | b23534a69554ad978f17a291b32ff63… | 2026-03-05 | 2026-03-05 |
| HASH | 183160373721b6f75314e14519ccaf5… | 2026-03-05 | 2026-03-05 |
| HASH | f4331fa7a90e05e0dbdadc6801dd1b3f | 2026-03-05 | 2026-03-05 |
| HASH | 9b57400da56221a27b87c5e732ca66c… | 2026-03-05 | 2026-03-05 |
| HASH | ad32d7d9e9027a24a02bc2c517def54… | 2026-03-05 | 2026-03-05 |
| HASH | 5f914616d9aec2d6e09e4e9ca61525f… | 2026-03-05 | 2026-03-05 |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| [email protected] | 2026-03-05 | 2026-03-05 | |
| URL | https://ip-checking-notificatio… | 2026-03-05 | 2026-03-05 |
| URL | https://ipcheck-six.vercel.app/… | 2026-03-05 | 2026-03-05 |
| URL | https://api.ipify.org?format=js… | 2026-03-05 | 2026-03-05 |
| URL | https://oracle-reg-check.vercel… | 2026-03-05 | 2026-03-05 |
| DOMAIN | whatchado.com | 2026-03-05 | 2026-03-05 |
| DOMAIN | winvps41507.hosted-by-eurohoste… | 2026-03-05 | 2026-03-05 |
| DOMAIN | dnswinvps41507.hosted-by-euroho… | 2026-03-05 | 2026-03-05 |
| IPv4 | 104.192.42.117 | 2026-03-05 | 2026-03-05 |