Inside DPRK's Fake Job Platform Targeting U.S. AI Talent
Essential information
- Published
- 26/11/2025 10:07
- Modified
- 21/12/2025 18:05
- Tags
- 2025-11-26 ai talent clickfix clipboard hijacking contagious interview cryptocurrency fake job platform malware delivery social engineering
- Related entities
- 2 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware, 7 others
Description
This analysis details a sophisticated DPRK-linked operation called Contagious Interview, which uses a fake job platform to target U.S. AI talent. The campaign mimics legitimate recruitment processes, offering job listings from well-known tech companies to lure victims. The platform, hosted at lenvny[.]com, is designed to appear as a legitimate AI-powered interview tool. It employs various techniques to establish credibility, including professional design, fake testimonials, and comparisons with real companies. The attack culminates in a malware delivery through a clipboard hijacking technique, triggered when victims attempt to record a video introduction. This operation specifically targets high-value professionals in AI and cryptocurrency sectors, aiming to gain access to strategic information and financial assets.