North Korean threat actors have launched an advanced cyber campaign called “Contagious Interview,” targeting software developers worldwide with a previously unknown backdoor called AkdoorTea. The campaign, tracked by Slovak cybersecurity firm ESET as “DeceptiveDevelopment,” specifically focuses on developers working on cryptocurrency and Web3 projects across Windows, Linux, and macOS platforms.
## How the Attack Works
The campaign operates through sophisticated social engineering tactics. Cybercriminals pose as recruiters on popular job platforms including LinkedIn, Upwork, Freelancer, and Crypto Jobs List, offering attractive employment opportunities to unsuspecting developers.
Once targets show interest, they’re asked to complete either:
– **Video assessments** through malicious links that display fake camera/microphone errors
– **Coding exercises** requiring them to clone infected GitHub projects
Both methods ultimately deliver malware to victims’ systems through deceptive “ClickFix” instructions that prompt users to run malicious commands.
## Advanced Malware Arsenal
The attackers deploy multiple sophisticated tools:
**Core Malware:**
– **AkdoorTea**: A newly discovered remote access trojan
– **BeaverTail and InvisibleFerret**: Data stealers targeting browsers and cryptocurrency wallets
– **WeaselStore**: Functions as both an infostealer and remote access tool
**Specialized Toolkits:**
– **TsunamiKit**: A comprehensive malware suite discovered in November 2024, designed for cryptocurrency theft and system persistence
– **Tropidoor**: The most advanced payload, sharing code with the notorious Lazarus Group’s LightlessCan tool
## Connection to Broader North Korean Operations
ESET researchers discovered significant overlaps between Contagious Interview and North Korea’s fraudulent IT worker scheme (WageMole). Intelligence gathered from the campaign helps North Korean operatives secure legitimate employment at companies using stolen identities—a threat active since 2017.
A recent case highlighted by Trellix involved a North Korean operative using the alias “Kyle Lankford” attempting to infiltrate a U.S. healthcare company as a Principal Software Engineer.
## Key Takeaways
The DeceptiveDevelopment group demonstrates a volume-driven approach, compensating for limited technical sophistication through:
– Large-scale social engineering operations
– Creative exploitation of open-source tools
– Adaptation of existing dark web projects
– Strategic targeting of human vulnerabilities
This campaign represents a hybrid threat combining traditional criminal activities like identity theft with advanced cyber operations, making it particularly dangerous for organizations in the cryptocurrency and technology sectors.
**Security professionals recommend enhanced vetting procedures for remote workers and increased awareness training for developers to recognize these sophisticated social engineering tactics.**
