Scworld
North Korea's Contagious Interview Campaign Uses JSON for Malware Distribution
First seen 2 Dec 2025, 18:33 UTC
•
•14.4
Export
Article Content
Browse articles
North Korean threat actors are utilizing JSON storage services to distribute malware as part of the ongoing Contagious Interview campaign, which has been active since 2023. The campaign involves impersonating hiring professionals to lure developers into executing malicious coding tasks through trojanized demo projects hosted on platforms like GitLab, utilizing heavily obfuscated JavaScript payloads retrieved from public JSON storage services.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments