Tag: Malware Delivery Channels

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
News

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

Two malicious cyber campaigns that resemble the ongoing North Korean threat cluster known as Contagious Interview (also known as Famous Chollima, HexagonalRodent, and Void Dokkaebi) have been identified by cybersecurity researchers. The threat actor has been discovered planning phishing attacks that use themes related to code reviews or developer role recruitment to target almost 100 companies in a variety of industries, including technology, education, banking, and cryptocurrencies, according to a research released by Proofpoint. The code for the action is UNK_DeadDrop. According to Proofpoint researchers Saher Naumaan and Carlos Rubio, the infection chain starts with emails that contain links to actor-controlled GitHub repositories hosting malicious scripts that cause cross-platfo...
North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

The Contagious Interview campaign's North Korean threat actors have once again modified their strategies by staging malware payloads using JSON storage services. According to a paper published on Thursday by NVISO researchers Bart Parys, Stef Collart, and Efstratios Lontzetidis, threat actors have recently turned to using JSON storage services like JSON Keeper, JSONsilo, and npoint.io to store and distribute malware from trojanized code projects. Under the guise of conducting a job assessment or working together on a project, the campaign basically entails contacting potential targets on professional networking sites like LinkedIn and instructing them to download a demo project hosted on platforms like GitHub, GitLab, or Bitbucket. A file called "server/config/.config.env" in one...