3 Sources
[1]
North Korean Hackers Spread Malware via Fake Crypto Firms and Job Interview Lures
North Korea-linked threat actors behind the Contagious Interview have set up front companies as a way to distribute malware during the fake hiring process. "In this new campaign, the threat actor group is using three front companies in the cryptocurrency consulting industry -- BlockNovas LLC
[2]
North Korean hackers set up 3 shell companies to scam crypto devs
Silent Push senior threat analyst Zach Edwards says the FBI has since shut down at least one of the companies. A subgroup of the North Korea-linked hacker organization Lazarus set up three shell companies, two in the US, to deliver malware to unsuspecting users. The three sham crypto consulting
[3]
Crypto Hack Alert: North Korean Hackers Target Developers With New Campaign
Via fake job intervies, the scammers steal individual's credentials which help them attack businesses. Amidst increasing crypto hacks, experts caution against a newly identified malware campaign. North Korean hackers, linked to the notorious Lazarus Group, have reportedly created three shell
Share
Copy Link
North Korean hackers set up fake crypto consulting firms to distribute malware through job interview lures, compromising wallets and stealing credentials. The FBI has seized one domain as part of ongoing efforts to combat this threat.

A group of North Korean hackers, linked to the notorious Lazarus Group, has launched a sophisticated malware campaign targeting cryptocurrency developers. The operation, known as "Contagious Interview," involves setting up front companies in the cryptocurrency consulting industry to spread malware through fake job interview processes
1
2
.Three shell companies have been identified as part of this operation:
These companies are being used to distribute three known malware families: BeaverTail, InvisibleFerret, and OtterCookie
1
. The malware is designed to steal sensitive information, including crypto wallet keys and clipboard data2
.The hackers have employed various tactics to make their operation appear legitimate:
2
3
1
1
The attackers lure victims by posting job listings on various platforms, including GitHub, job boards, and freelancer websites
2
.During the fake job application process, applicants are presented with an error message when trying to record an introduction video. The "solution" involves a simple click-fix that, when executed, leads to the deployment of malware
2
3
.At least one developer has reportedly had their MetaMask wallet compromised as a result of this campaign
1
2
. The stolen credentials can potentially be used to launch further attacks on legitimate businesses in the cryptocurrency sector3
.Related Stories
The FBI has taken action against this threat by seizing the domain of BlockNovas, one of the fake companies involved in the operation
1
2
. An FBI official described North Korean cyber operations as "one of the most advanced persistent threats" facing the United States3
.This campaign is part of a larger pattern of North Korean cyber activities targeting the cryptocurrency sector. Other known tactics include:
1
2
2
Experts advise cryptocurrency developers and companies to exercise caution when engaging in online job applications or video interviews. Verifying the legitimacy of potential employers and being wary of unexpected software installations during the application process are crucial steps in protecting against these sophisticated attacks
1
2
3
.Summarized by
Navi
[2]