North Korea Tried to Hack Our CEO Through a Fake Job Interview on LinkedIn

2026-03-05 Allsecure

https://www.allsecure.io/blog/lazarus-linkedin-attack/

Thumbnail for North Korea Tried to Hack Our CEO Through a Fake Job Interview on LinkedIn

A fake LinkedIn recruiter posing as a 0G Labs representative targeted a crypto/Web3 CEO with a technical assessment that required cloning a Bitbucket repository and opening it in VS Code or Cursor. The repository hid three independent execution paths: a VS Code folder-open task that piped a Vercel stager into Node, an npm prepare hook, and route code that exfiltrated process.env secrets before executing server-supplied JavaScript. The captured BeaverTail chain fingerprinted the host, beaconed every five seconds to 104.192.42.117:3000, received a second-stage Node.js bootstrapper, and attempted to run an in-memory C2 agent with hidden child processes, ID rotation, and a kill switch. Operators killed the analysis sessions after recognizing AWS datacenter infrastructure, showing active victim triage tied to the DPRK Contagious Interview campaign.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.ipify.org 2019-12-11 2026-03-17
HASH 66d991be156e9b602dc0d22c56424a5… 2026-03-05 2026-03-05
HASH 4f57c2602488c1c72bf4bfbb2c720cd… 2026-03-05 2026-03-05
HASH 0440af4634fdc23313f008d5341439d… 2026-03-05 2026-03-05
HASH c913a6b89e6f2d51cb9d6b45f75970c… 2026-03-05 2026-03-05
HASH 98c5dfa2ad170d221c1110f28b8f129b 2026-03-05 2026-03-05
HASH 76bb590bdf7dd413232da22466645d3… 2026-03-05 2026-03-05
HASH 28e73ce85db813ba0839ee077428eaa… 2026-03-05 2026-03-05
HASH b460480112ee5c5e47baf0a13699b88… 2026-03-05 2026-03-05
HASH 37eb8e11b40527de0881189064c657f… 2026-03-05 2026-03-05
HASH b23534a69554ad978f17a291b32ff63… 2026-03-05 2026-03-05
HASH 183160373721b6f75314e14519ccaf5… 2026-03-05 2026-03-05
HASH f4331fa7a90e05e0dbdadc6801dd1b3f 2026-03-05 2026-03-05
HASH 9b57400da56221a27b87c5e732ca66c… 2026-03-05 2026-03-05
HASH ad32d7d9e9027a24a02bc2c517def54… 2026-03-05 2026-03-05
HASH 5f914616d9aec2d6e09e4e9ca61525f… 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
EMAIL [email protected] 2026-03-05 2026-03-05
URL https://ip-checking-notificatio… 2026-03-05 2026-03-05
URL https://ipcheck-six.vercel.app/… 2026-03-05 2026-03-05
URL https://api.ipify.org?format=js… 2026-03-05 2026-03-05
URL https://oracle-reg-check.vercel… 2026-03-05 2026-03-05
DOMAIN whatchado.com 2026-03-05 2026-03-05
DOMAIN winvps41507.hosted-by-eurohoste… 2026-03-05 2026-03-05
DOMAIN dnswinvps41507.hosted-by-euroho… 2026-03-05 2026-03-05
IPv4 104.192.42.117 2026-03-05 2026-03-05

Related Actors

Related Reports

« Back