Act
active
North Korea Contagious Interview Campaign: 30K Devices, $10.71M Stolen
- Engineer — Learn: No KEV listing or PoC signals; the campaign targets individuals via fake job interviews delivering malware, so engineering teams should be aware of the social-engineering vector but no immediate patch or config action is required today.
- SOC/IR — Act: Joint advisory indicates active, widespread campaign — hunt for Contagious Interview TTPs (fake recruiter lures, malicious npm/Python packages, BeaverTail/InvisibleFerret malware) in endpoint and email telemetry, and sweep for IOCs from the advisory across devices belonging to engineering and crypto-adjacent staff.
- Leader — Plan: A confirmed North Korean campaign at this scale targeting engineers and crypto wallets warrants a policy review of how staff handle unsolicited recruiting outreach and code from unknown sources; brief security awareness owners to update training for engineering and finance teams this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.