Contagious Interview steps outside the developer workflow
Jamf Threat Labs discovered a cluster of 14 trojanized macOS applications distributed as DMG and PKG files impersonating legitimate software like The Unarchiver, Sketch, and Bartender. These samples are linked to the Contagious Interview campaign, a DPRK-attributed operation using fake job interviews as a pretext. The malware chain begins with unsigned, modified applications containing hidden executables that download staging scripts from infrastructure at 162.0.239[.]85. The attack progresses through multiple stages, ultimately deploying OtterCookie malware, which provides remote access capabilities, credential stealing from browsers and crypto wallets, filesystem scanning, and clipboard monitoring. The delivery method represents an evolution from previous Git hook and VS Code task-based attacks to standalone installer packages requiring manual quarantine attribute removal to execute.
Indicators of Compromise
- domain: pobelstudio.com
- ip: 147.124.202.205
- ip: 162.0.239.85
- hash: 01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b
- hash: 08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9
- hash: 0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39
- hash: 0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab
- hash: 0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29
- hash: 1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91
- hash: 24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf
- hash: 3a7fedfeb42f13b2c368c195ec83b8e8c952df7fd506133210868f3eeb06b51d
- hash: 3cda9d3522d471a0018bc58499a424f8084b29e21776d8d63d09fe2d7eca4b49
- hash: 42620128470e26d473a128f354b77ca2c5fe9e5782e7addc1e3f863dbd0cd9b0
- hash: 46d382b234dcd63e66b17799b2e6cefe24ae60e10bef758c6ccf8e72ba0aaa6c
- hash: 4c025bda19d6b7b1f9cc209876099b20130a198c18ae22b7809470dde93c62db
- hash: 5ab8c5808cc00825c608027d7da8611a5386de65a724fed999828310b3cb4ddb
- hash: 6b33812538be1983c94cedc82f480fd98b7ccdd3df7fa4fda863262818d07ba1
- hash: 7030b07575e3c6558fecfd1cabc7463f10c7ca37262da7e57221a85464b7982d
- hash: 791f2c56e945a2b6e99d93b10e6f42c383aa9a083ae98fc74f8720f92789c645
- hash: 815a41a0c0426ffec3c9ad08e1fb125a040cf0e41acce2a86b891aeb08648d61
- hash: 89d36570b91f59f78eaaafba19e91032dce3e6b42d4b7905d38724399bb8c8c2
- hash: 9ff8a6e839ebfaa185fbd53c35f1e671fe9ce6851738df07d086cae67db3e06a
- hash: ab5e0684869238c1a1cabadfa0b2e4351490a6343d210ad09c09455ed352b338
- hash: b07f46962c409cb854e34e06abcfc616edcc5a554a43cfac8f4f26cb818a340d
- hash: d55d6419b20e7bf07025d3e464cd4bc05bc96216bf5f85dd7f9a4cbdba10d8ea
- hash: d9f6c4e60ca24364751e9a3f1550f3600726cb5d185407bc82078aa95ef09e53
- hash: e328e5ecf66ac5989aa5f8fb2a7c742d475647b53c929df544b6128db16750d6
- hash: ed3cfda8fcd1936777e3ebabb9a307325c4c2cd793416386c80bf906e4df279b
- hash: f5686109776f83123d30568e552708a7ad78964396d0f3bfd37d0332f44f8ad6
- hash: f9e29c72088f4a7f7789755cd08057f0125c42b352187951623d9290ed0ace1f
- hash: fab2e8e1ac22c5d14fd6531efe4e8e05ca9246786154b2d2f3b7f425777f4818
- url: http://147.124.202.205/api/service/makelog
- url: http://162.0.239.85:3000/task/package.json
- url: http://162.0.239.85:3000/task/tokenlinux?token=30621301&st=eyJhbGciOiJIUzI1NiIs...
- domain: kikaiverse.com
- domain: lalitae.com
- domain: pobel.studio
- domain: softcus.net
- domain: w3pi.social
- domain: miniapp.w3pi.social
Contagious Interview steps outside the developer workflow
Description
Jamf Threat Labs discovered a cluster of 14 trojanized macOS applications distributed as DMG and PKG files impersonating legitimate software like The Unarchiver, Sketch, and Bartender. These samples are linked to the Contagious Interview campaign, a DPRK-attributed operation using fake job interviews as a pretext. The malware chain begins with unsigned, modified applications containing hidden executables that download staging scripts from infrastructure at 162.0.239[.]85. The attack progresses through multiple stages, ultimately deploying OtterCookie malware, which provides remote access capabilities, credential stealing from browsers and crypto wallets, filesystem scanning, and clipboard monitoring. The delivery method represents an evolution from previous Git hook and VS Code task-based attacks to standalone installer packages requiring manual quarantine attribute removal to execute.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/"]
- Adversary
- DPRK
- Pulse Id
- 6a99efa1445d8ef021e25d53
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainpobelstudio.com | — | |
domainkikaiverse.com | — | |
domainlalitae.com | — | |
domainpobel.studio | — | |
domainsoftcus.net | — | |
domainw3pi.social | — | |
domainminiapp.w3pi.social | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip147.124.202.205 | — | |
ip162.0.239.85 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b | — | |
hash08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9 | — | |
hash0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39 | — | |
hash0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab | — | |
hash0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29 | — | |
hash1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91 | — | |
hash24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf | — | |
hash3a7fedfeb42f13b2c368c195ec83b8e8c952df7fd506133210868f3eeb06b51d | — | |
hash3cda9d3522d471a0018bc58499a424f8084b29e21776d8d63d09fe2d7eca4b49 | — | |
hash42620128470e26d473a128f354b77ca2c5fe9e5782e7addc1e3f863dbd0cd9b0 | — | |
hash46d382b234dcd63e66b17799b2e6cefe24ae60e10bef758c6ccf8e72ba0aaa6c | — | |
hash4c025bda19d6b7b1f9cc209876099b20130a198c18ae22b7809470dde93c62db | — | |
hash5ab8c5808cc00825c608027d7da8611a5386de65a724fed999828310b3cb4ddb | — | |
hash6b33812538be1983c94cedc82f480fd98b7ccdd3df7fa4fda863262818d07ba1 | — | |
hash7030b07575e3c6558fecfd1cabc7463f10c7ca37262da7e57221a85464b7982d | — | |
hash791f2c56e945a2b6e99d93b10e6f42c383aa9a083ae98fc74f8720f92789c645 | — | |
hash815a41a0c0426ffec3c9ad08e1fb125a040cf0e41acce2a86b891aeb08648d61 | — | |
hash89d36570b91f59f78eaaafba19e91032dce3e6b42d4b7905d38724399bb8c8c2 | — | |
hash9ff8a6e839ebfaa185fbd53c35f1e671fe9ce6851738df07d086cae67db3e06a | — | |
hashab5e0684869238c1a1cabadfa0b2e4351490a6343d210ad09c09455ed352b338 | — | |
hashb07f46962c409cb854e34e06abcfc616edcc5a554a43cfac8f4f26cb818a340d | — | |
hashd55d6419b20e7bf07025d3e464cd4bc05bc96216bf5f85dd7f9a4cbdba10d8ea | — | |
hashd9f6c4e60ca24364751e9a3f1550f3600726cb5d185407bc82078aa95ef09e53 | — | |
hashe328e5ecf66ac5989aa5f8fb2a7c742d475647b53c929df544b6128db16750d6 | — | |
hashed3cfda8fcd1936777e3ebabb9a307325c4c2cd793416386c80bf906e4df279b | — | |
hashf5686109776f83123d30568e552708a7ad78964396d0f3bfd37d0332f44f8ad6 | — | |
hashf9e29c72088f4a7f7789755cd08057f0125c42b352187951623d9290ed0ace1f | — | |
hashfab2e8e1ac22c5d14fd6531efe4e8e05ca9246786154b2d2f3b7f425777f4818 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://147.124.202.205/api/service/makelog | — | |
urlhttp://162.0.239.85:3000/task/package.json | — | |
urlhttp://162.0.239.85:3000/task/tokenlinux?token=30621301&st=eyJhbGciOiJIUzI1NiIs... | — |
Threat ID: 6a9ab102acd9273b498670ce
Added to database: 09/04/2026, 11:52:34 UTC
Last updated: 09/04/2026, 15:47:42 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.