Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories — Threadlinqs Intelligence
As of 2026-05-30, Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories is a high-severity apt threat attributed to WageMole (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0402 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: WageMole · North Korea (DPRK) · FINANCIAL
Void Dokkaebi — tracked by Unit 42 as Contagious Interview (CL-STA-0240) and by CrowdStrike as Famous Chollima — is a DPRK-aligned cluster that social-engineers software developers via fake LinkedIn,
Void Dokkaebi is the Trend Micro designation for a DPRK-aligned intrusion cluster overlapping with Palo Alto Unit 42's Contagious Interview (CL-STA-0240) and CrowdStrike's Famous Chollima. The cluster has been active since at least late 2022 and, per the 2026-04-21 Trend Micro writeup, has evolved its malware arsenal and lure infrastructure while maintaining the core 'fake job interview' social-engineering chain.
Initial access begins on professional and developer-facing platforms — LinkedIn, X (Twitter), GitHub, Upwork, Freelancer.com, We Work Remotely, and Telegram developer groups. Operators pose as recruiters or hiring managers at plausible but fictitious companies, or spoof well-known crypto and fintech brands, and open dialogue with targeted developers (particularly those listing JavaScript, Node.js, React, Python, Go, or Web3/Solidity skills). After rapport-building over several days, the operator schedules a 'technical interview' — frequently on hijacked or look-alike MiroTalk, freeconference, or Google Meet domains — and asks the candidate to clone a GitHub or Bitbucket repository presented as a 'coding assignment,' 'bug fix task,' or 'fork of our production code.'
The repositories are otherwise-functional Node.js, Python, or Go projects (often cryptocurrency dashboards, trading bots, or Web3 wallets) that contain obfuscated malicious code buried inside utility files, post-install hooks, or deeply nested package subdirectories. Execution paths include: (a) malicious `postinstall` or `preinstall` scripts in `package.json` that fire on `npm install`; (b) JavaScript loaders hidden inside minified or heavily commented test files; (c) Python `setup.py` hooks or runtime-imported modules; (d) Go-compiled droppers for GolangGhost variants. Developers running the repo — frequently on their own workstations rather than an isolated VM — execute the loader under their own user context.
Stage 1 (BeaverTail) is a heavily obfuscated JavaScript infostealer (and, in newer cross-platform variants, a Qt/Electron bundle) that enumerates and exfiltrates Chromium, Brave, Edge, Firefox, and Opera browser profile data (cookies, saved logins, autofill, extension data), targets ~20 cryptocurrency wallet browser extensions (MetaMask, Phantom, Binance Chain, Coinbase Wallet, TronLink, Trust Wallet, Exodus browser ext, Ronin, etc.), and harvests macOS Keychain, SSH keys, AWS/GCP credential files, and iCloud Keychain artifacts where reachable. BeaverTail then downloads Stage 2 from an operator-controlled C2 host.
Stage 2 (InvisibleFerret) is a Python-based modular backdoor delivered as compressed, base64-encoded payload chunks. Functionality includes: command execution, file enumeration and exfiltration, keylogging, screen capture, browser-credential and crypto-wallet stealing (complementary to BeaverTail), and the silent installation of AnyDesk as a persistent remote-management channel. InvisibleFerret establishes persistence via OS-specific mechanisms (LaunchAgents on macOS, Registry Run keys on Windows, systemd user units or cron on Linux).
OtterCookie — first documented by NTT Security in December 2024 and evolved across 2025 — is a newer JavaScript stealer variant occasionally deployed alongside or in place of BeaverTail. OtterCookie uses Socket.IO for C2, specifically targets cryptocurrency-related keychain items and wallet files, and carries an extended anti-analysis layer including VM detection. GolangGhost is a Go-language rewrite family observed in 2025-2026 that consolidates the stealer-plus-backdoor functionality into a single cross-platform (macOS-focused) binary — a direct response to endpoint detection improvements against the noisy JS/Python chain.
Stolen credentials, cryptocurrency, and system access are monetized directly (wallet draining) and used operationally to stage follow-on intrusions, including cases where the same victim is later re-targeted by DPRK IT-worker operators to exfiltrate corporate source code and IP. Re
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-1357
Target sectors: technology, software development, cryptocurrency, blockchain, decentralized finance (DeFi), financial services, gaming, freelance / contractor developers, startups, fintech
Target regions: North America, Europe, South Korea, Japan, United Kingdom, India, Southeast Asia, Global (developer-centric)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1589, T1593.001, T1585.001, T1583.003, T1587.001, T1608.001, T1566.003, T1195.002, T1204.002, T1059.007