Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews — Threadlinqs Intelligence
As of 2026-05-30, Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews is a high-severity apt threat attributed to WageMole (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 40 indicators of compromise.
Threat ID: TL-2026-0213 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: WageMole · North Korea · FINANCIAL
North Korean threat actors are conducting an active social engineering campaign dubbed Contagious Interview, posing as recruiters from cryptocurrency and AI companies to deliver OtterCookie,
Contagious Interview is a persistent, multi-stage social engineering campaign attributed to DPRK-aligned threat actors tracked as Famous Chollima, Tenacious Pungsan, and DEV#POPPER (MITRE G1052). Active since at least November 2023, the campaign has evolved significantly through 2024-2026 with expanding infrastructure, new malware families, and increasingly sophisticated delivery mechanisms.
The attack chain begins with threat actors establishing fake front companies — BlockNovas LLC (blocknovas.com), Angeloper Agency (angeloper.com), and SoftGlide LLC (softglide.co) — and creating AI-generated employee personas to post job listings on platforms including LinkedIn, CryptoJobsList, Upwork, Freelancer, and GitHub. Targets are primarily software developers in the cryptocurrency, blockchain, Web3, and artificial intelligence sectors.
Victims are lured through a multi-stage interview process: initial contact via LinkedIn or job boards, followed by a video interview that triggers a fake camera/microphone error. The victim is then prompted to install malicious software disguised as VCam, CameraAccess, or ChromeUpdate — or to execute a ClickFix-style Terminal command that downloads and executes the first-stage payload.
The malware arsenal includes four primary families: BeaverTail (JavaScript-based infostealer distributed via malicious npm packages using HexEval and XORIndex obfuscation), InvisibleFerret (Python-based multi-stage backdoor providing persistent remote access), OtterCookie (JavaScript/Node.js backdoor communicating via Socket.IO on non-standard port 1224 for credential theft, clipboard exfiltration, and shell command execution), and the FERRET family on macOS — FrostyFerret (Golang first-stage dropper), FriendlyFerret (Go backdoor masquerading as com.apple.secd), and FlexibleFerret (signed with a valid but now-revoked Apple Developer certificate, Team ID 58CD8AD5Z4, establishing LaunchAgent persistence and exfiltrating data via Dropbox API).
The npm supply chain component is particularly aggressive: over 338 malicious packages with 50,000+ cumulative downloads have been identified since July 2025, using namesquatting against legitimate libraries (passports-js, bcrypts-js, blockscan-api, postcss-optimizer). These packages reconstruct BeaverTail in memory, which then drops InvisibleFerret for persistent access.
C2 infrastructure spans multiple domains and IPs, with primary servers at lianxinxiao.com (37.221.126.117), chainlink-api-v3.cloud, zoom.callservice.us, and camdriversupport.com. Actors route through Astrill VPN exit nodes across 19+ IPs to obscure attribution. The campaign has resulted in confirmed financial losses including cryptocurrency wallet compromises and source code theft from developer endpoints.
---
**Revalidated on 2026-03-12**
Since the last update, the Contagious Interview campaign has undergone five significant evolutions that expand its threat profile:
**Law Enforcement Action (April 2025):** The FBI seized the BlockNovas.com domain on April 23, 2025, as part of a law enforcement action against DPRK cyber actors for using it to deceive individuals with fake job postings and distribute malware. However, the Angeloper and SoftGlide infrastructure remained operational, and the campaign rapidly spun up replacement infrastructure.
**Operational Exposure (Mid-2025):** SentinelLABS, in collaboration with Validin, analyzed exposed log files from Contagious Interview servers revealing 230+ confirmed victims between January and March 2025 alone. The research showed threat actors using Slack channels for real-time coordination and actively monitoring cyber threat intelligence platforms (Validin, VirusTotal, Maltrail) -- registering accounts on Validin within 24 hours of publications referencing their infrastructure. This counter-intelligence awareness underscores the sophistication of the operation.
**IDE Infection Vector (Late 2025):** The campaign adopted VS Code and Cursor IDE task file abuse as a
Weaknesses (CWE)
CWE-506, CWE-829
Target sectors: cryptocurrency, artificial-intelligence, software-development, blockchain, web3, financial-services, technology
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 40 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1583, T1585, T1585, T1585, T1587, T1588, T1608, T1589