Contagious Interview — APT Profile
Contagious Interview is a North Korea-aligned operation, active since late 2022, that targets software developers and cryptocurrency-sector job seekers with fake recruiters and staged hiring tests, delivering the BeaverTail infostealer and InvisibleFerret backdoor on Windows, Linux, and macOS to steal credentials and cryptocurrency. The operators, tracked by NTT as WaterPlum, added the OtterCookie backdoor in late 2024, reaching v4 by April 2025 with sandbox evasion and Chrome/MetaMask credential theft. A ClickFix variant documented by Sekoia in March 2025 fakes a camera-access error during video interviews so victims paste commands installing GolangGhost or FrostyFerret. Socket counted 338 malicious npm packages with over 50,000 downloads by October 2025, and in March 2026 Microsoft documented delivery via repositories abusing VS Code workspace trust to auto-run malicious tasks. ESET assesses with medium confidence that the operators collaborate with DPRK IT-worker teams, which reuse stolen victim data in employment fraud.Also tracked as
DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, WaterPlum
Tools & malware
- BeaverTail Infostealer
- GolangGhost remote access trojan
- HexEval Loader Loader
- InvisibleFerret Backdoor
- OtterCookie backdoor
- XORIndex Loader Loader
Vendor research
- Elastic Security Labs Elastic Security Labs
- OtterCookie, new malware used in Contagious Interview campaign NTT Security Holdings
- From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic Sekoia
- Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview DataDog
- Inside the Scam: North Korea’s IT Worker Threat Recorded Future
- DeceptiveDevelopment targets freelance developers ESET
- Exposing DPRK's Cyber Syndicate and Hidden IT Workforce dtex
- Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms Sentinel One
- From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West Zscaler
- Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors PaloAlto
- Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware PaloAlto
- Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors Securonix
- Lazarus APT: Techniques for Hunting Contagious Interview Validin
- Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2 Esentire