Two IOCs In, Five C2 Servers Out: Mapping DPRK's Contagious Interview Campaign From InvisibleFerret to a Kimsuky Crossover
2026-04-01 • Break Glass Intelligence •
Breakglass maps a DPRK Contagious Interview campaign in which North Korean operators pose as recruiters and lure software developers into running ClickFix-style setup commands during fake job interviews. The observed chain uses BeaverTail and InvisibleFerret tooling across Windows, Linux, and macOS to steal passwords, SSH keys, cloud credentials, browser data, and cryptocurrency wallets. Infrastructure includes five C2 or exfiltration servers across several providers, five driver-themed .cloud domains registered through Namecheap, and a Fly.io endpoint masquerading as an NVIDIA SDK delivery service. The excerpt also describes staging through a deleted GitHub repository under a fabricated persona, numeric-only User-Agent payload selectors, and a Mach-O sample tagged with both ContagiousInterview and Kimsuky/VelvetChollima as possible evidence of DPRK tool sharing or overlap.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.59.163.23 | 2026-01-21 | 2026-04-01 |
| IPv4 | 95.216.37.186 | 2026-01-20 | 2026-04-01 |
| URL | https://nvidiasdk.fly.dev/nvs | 2025-09-17 | 2026-04-01 |
| DOMAIN | nvidiasdk.fly.dev | 2025-09-17 | 2026-04-01 |
| IPv4 | 172.86.93.139 | 2025-09-17 | 2026-04-01 |
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |