216.73.216.6

Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms

· Published 04/09/2025 17:54 · Modified 04/09/2025 21:44

Export JSON

Essential information

Published
04/09/2025 17:54
Modified
04/09/2025 21:44
Tags
2025-09-04 clickfix contagiousdrop cryptocurrency cyber espionage infrastructure monitoring job seeker targeting lazarus north korea social engineering
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 2 others

Description

North Korean threat actors associated with the Contagious Interview campaign cluster are actively monitoring cyber threat intelligence platforms to detect infrastructure exposure and scout for new assets. They operate in coordinated teams, likely using Slack for real-time collaboration, and leverage multiple intelligence sources including Validin, VirusTotal, and Maltrail. Despite being aware of their infrastructure's detectability, they make only limited changes to reduce detection risk, focusing instead on rapidly deploying new infrastructure to sustain operations. The actors' effectiveness is evident in their engagement of over 230 victims between January and March 2025, primarily targeting individuals in the industry. Their activities involve sophisticated tactics, including the technique, to trick targets into executing malware.

External references