North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
The Contagious Interview campaign's North Korean threat actors have once again modified their strategies by staging malware payloads using JSON storage services.
According to a paper published on Thursday by NVISO researchers Bart Parys, Stef Collart, and Efstratios Lontzetidis, threat actors have recently turned to using JSON storage services like JSON Keeper, JSONsilo, and npoint.io to store and distribute malware from trojanized code projects.
Under the guise of conducting a job assessment or working together on a project, the campaign basically entails contacting potential targets on professional networking sites like LinkedIn and instructing them to download a demo project hosted on platforms like GitHub, GitLab, or Bitbucket.
A file called "server/config/.config.env" in one...

