Contagious Interview — APT Profile

Contagious Interview is a North Korea-aligned operation, active since late 2022, that targets software developers and cryptocurrency-sector job seekers with fake recruiters and staged hiring tests, delivering the BeaverTail infostealer and InvisibleFerret backdoor on Windows, Linux, and macOS to steal credentials and cryptocurrency. The operators, tracked by NTT as WaterPlum, added the OtterCookie backdoor in late 2024, reaching v4 by April 2025 with sandbox evasion and Chrome/MetaMask credential theft. A ClickFix variant documented by Sekoia in March 2025 fakes a camera-access error during video interviews so victims paste commands installing GolangGhost or FrostyFerret. Socket counted 338 malicious npm packages with over 50,000 downloads by October 2025, and in March 2026 Microsoft documented delivery via repositories abusing VS Code workspace trust to auto-run malicious tasks. ESET assesses with medium confidence that the operators collaborate with DPRK IT-worker teams, which reuse stolen victim data in employment fraud.

Also tracked as

DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, WaterPlum

Tools & malware

Vendor research

Read the full analysis on IntelFusions