North Korean Hackers Weaponize Blockchain to Deploy Evolved Malware Arsenal in Stealth Attacks

# North Korean Hackers Evolve Malware Arsenal in Ongoing “Contagious Interview” Campaign

North Korean cybercriminals behind the notorious “Contagious Interview” campaign are actively upgrading their malware toolkit, merging capabilities from two separate programs to create more sophisticated attack tools, according to new research from Cisco Talos.

## Campaign Evolution and New Capabilities

The threat group, known by multiple aliases including Famous Chollima, Gwisin Gang, and UNC5342, has been observed combining features from their BeaverTail and OtterCookie malware families. The latest version of OtterCookie now includes enhanced keylogging and screenshot capabilities, marking a significant evolution in the group’s technical arsenal.

In a groundbreaking development, Google Threat Intelligence and Mandiant discovered the group using “EtherHiding” – a technique that leverages blockchain networks like Ethereum and BNB Smart Chain as command-and-control servers. This represents the first documented case of a nation-state actor using this method, which was previously limited to cybercrime groups.

## The Contagious Interview Scam

Operating since late 2022, the Contagious Interview campaign targets job seekers through elaborate recruitment scams. Attackers impersonate legitimate hiring organizations, tricking victims into downloading malware disguised as technical assessments or coding tasks. This social engineering approach has proven highly effective at stealing sensitive data and cryptocurrency.

Recent campaigns have incorporated ClickFix techniques and deployed various malware strains including GolangGhost, PylangGhost, and TsunamiKit.

## Real-World Attack Analysis

Cisco Talos analyzed a recent attack targeting a Sri Lankan organization, likely infected when an employee fell victim to a fake job offer. The attack involved a malicious Node.js application called “Chessfi” hosted on Bitbucket, which included a dependency from a compromised npm package called “node-nvm-ssh.”

This malicious package, published by a user named “trailer,” was downloaded 306 times before being removed by npm maintainers. It was among 338 malicious Node libraries recently identified by Socket as connected to the campaign.

## Advanced Malware Capabilities

The new OtterCookie version (v5) demonstrates significant evolution from basic data collection to a comprehensive theft and remote access platform. Key features include:

– **Enhanced Data Theft**: Browser profile enumeration, cryptocurrency wallet targeting, and web browser data extraction
– **Remote Access**: AnyDesk installation for persistent access and Python backdoor deployment
– **Advanced Monitoring**: Keylogging, screenshot capture, and clipboard monitoring using legitimate npm packages
– **File System Scanning**: Systematic search for files containing cryptocurrency-related terms like “metamask,” “bitcoin,” and “backup”
– **Remote Command Execution**: Shell module for receiving and executing commands from attackers

## Delivery Method Experimentation

Researchers also discovered evidence of the group testing new delivery methods, including Qt-based BeaverTail variants and malicious Visual Studio Code extensions. However, these may represent experimental work rather than active deployment.

## Implications for Cybersecurity

This campaign highlights the growing sophistication of nation-state actors and their willingness to adopt novel techniques like blockchain-based infrastructure. Organizations should remain vigilant against social engineering attacks targeting employees, particularly those involving fake job opportunities or technical assessments.

The merger of malware capabilities and adoption of legitimate tools for malicious purposes demonstrates how threat actors continue to evolve their tactics to evade detection and maximize impact.

Share This Article