Two IOCs In, Five C2 Servers Out: Mapping DPRK's Contagious Interview Campaign From InvisibleFerret to a Kimsuky Crossover

2026-04-01 Break Glass Intelligence

https://intel.breakglass.tech/post/invisibleferret-contagious-interview-dprk-lazarus-kimsuky-crossover

Thumbnail for Two IOCs In, Five C2 Servers Out: Mapping DPRK's Contagious Interview Campaign From InvisibleFerret to a Kimsuky Crossover

Breakglass maps a DPRK Contagious Interview campaign in which North Korean operators pose as recruiters and lure software developers into running ClickFix-style setup commands during fake job interviews. The observed chain uses BeaverTail and InvisibleFerret tooling across Windows, Linux, and macOS to steal passwords, SSH keys, cloud credentials, browser data, and cryptocurrency wallets. Infrastructure includes five C2 or exfiltration servers across several providers, five driver-themed .cloud domains registered through Namecheap, and a Fly.io endpoint masquerading as an NVIDIA SDK delivery service. The excerpt also describes staging through a deleted GitHub repository under a fabricated persona, numeric-only User-Agent payload selectors, and a Mach-O sample tagged with both ContagiousInterview and Kimsuky/VelvetChollima as possible evidence of DPRK tool sharing or overlap.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.59.163.23 2026-01-21 2026-04-01
IPv4 95.216.37.186 2026-01-20 2026-04-01
URL https://nvidiasdk.fly.dev/nvs 2025-09-17 2026-04-01
DOMAIN nvidiasdk.fly.dev 2025-09-17 2026-04-01
IPv4 172.86.93.139 2025-09-17 2026-04-01
IPv4 95.164.17.24 2024-07-15 2026-04-01

Related Actors

Related Reports

2026-04-17 • 60% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tag: Kimsuky • Same author: Break Glass Intelligence • Published within a month
« Back