Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Contagious Interview steps outside the developer workflow

0
Medium
Published: 09/03/2026 (09/03/2026, 22:07:29 UTC)
Source: AlienVault OTX General

Description

Jamf Threat Labs discovered a cluster of 14 trojanized macOS applications distributed as DMG and PKG files impersonating legitimate software like The Unarchiver, Sketch, and Bartender. These samples are linked to the Contagious Interview campaign, a DPRK-attributed operation using fake job interviews as a pretext. The malware chain begins with unsigned, modified applications containing hidden executables that download staging scripts from infrastructure at 162.0.239[.]85. The attack progresses through multiple stages, ultimately deploying OtterCookie malware, which provides remote access capabilities, credential stealing from browsers and crypto wallets, filesystem scanning, and clipboard monitoring. The delivery method represents an evolution from previous Git hook and VS Code task-based attacks to standalone installer packages requiring manual quarantine attribute removal to execute.

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/"]
Adversary
DPRK
Pulse Id
6a99efa1445d8ef021e25d53
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpobelstudio.com
domainkikaiverse.com
domainlalitae.com
domainpobel.studio
domainsoftcus.net
domainw3pi.social
domainminiapp.w3pi.social

Ip

ValueDescriptionCopy
ip147.124.202.205
ip162.0.239.85

Hash

ValueDescriptionCopy
hash01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b
hash08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9
hash0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39
hash0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab
hash0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29
hash1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91
hash24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf
hash3a7fedfeb42f13b2c368c195ec83b8e8c952df7fd506133210868f3eeb06b51d
hash3cda9d3522d471a0018bc58499a424f8084b29e21776d8d63d09fe2d7eca4b49
hash42620128470e26d473a128f354b77ca2c5fe9e5782e7addc1e3f863dbd0cd9b0
hash46d382b234dcd63e66b17799b2e6cefe24ae60e10bef758c6ccf8e72ba0aaa6c
hash4c025bda19d6b7b1f9cc209876099b20130a198c18ae22b7809470dde93c62db
hash5ab8c5808cc00825c608027d7da8611a5386de65a724fed999828310b3cb4ddb
hash6b33812538be1983c94cedc82f480fd98b7ccdd3df7fa4fda863262818d07ba1
hash7030b07575e3c6558fecfd1cabc7463f10c7ca37262da7e57221a85464b7982d
hash791f2c56e945a2b6e99d93b10e6f42c383aa9a083ae98fc74f8720f92789c645
hash815a41a0c0426ffec3c9ad08e1fb125a040cf0e41acce2a86b891aeb08648d61
hash89d36570b91f59f78eaaafba19e91032dce3e6b42d4b7905d38724399bb8c8c2
hash9ff8a6e839ebfaa185fbd53c35f1e671fe9ce6851738df07d086cae67db3e06a
hashab5e0684869238c1a1cabadfa0b2e4351490a6343d210ad09c09455ed352b338
hashb07f46962c409cb854e34e06abcfc616edcc5a554a43cfac8f4f26cb818a340d
hashd55d6419b20e7bf07025d3e464cd4bc05bc96216bf5f85dd7f9a4cbdba10d8ea
hashd9f6c4e60ca24364751e9a3f1550f3600726cb5d185407bc82078aa95ef09e53
hashe328e5ecf66ac5989aa5f8fb2a7c742d475647b53c929df544b6128db16750d6
hashed3cfda8fcd1936777e3ebabb9a307325c4c2cd793416386c80bf906e4df279b
hashf5686109776f83123d30568e552708a7ad78964396d0f3bfd37d0332f44f8ad6
hashf9e29c72088f4a7f7789755cd08057f0125c42b352187951623d9290ed0ace1f
hashfab2e8e1ac22c5d14fd6531efe4e8e05ca9246786154b2d2f3b7f425777f4818

Url

ValueDescriptionCopy
urlhttp://147.124.202.205/api/service/makelog
urlhttp://162.0.239.85:3000/task/package.json
urlhttp://162.0.239.85:3000/task/tokenlinux?token=30621301&st=eyJhbGciOiJIUzI1NiIs...

Threat ID: 6a9ab102acd9273b498670ce

Added to database: 09/04/2026, 11:52:34 UTC

Last updated: 09/04/2026, 15:47:42 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses