Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures

## Cybersecurity: North Korean Hacking Campaigns

Cybersecurity: North Korean Hacking Campaigns

North Korean state-sponsored hackers are executing large-scale campaigns that exploit IT hiring processes to deploy JavaScript-based malware, steal code and credentials, and generate covert revenue. These operations involve impersonating recruiters and hiring managers, particularly targeting software developers to run compromised code during technical interviews.

The "Contagious Interview" campaign involves candidates being asked to clone repositories or debug projects that contain malware loaders such as BeaverTail and Ottercookie. When executed, these projects can extract credentials, steal source code, and provide remote control over systems, affecting Windows, Linux, and macOS platforms.

According to GitLab's 2025 threat intelligence, attackers use JavaScript-based codebases and loaders, employing methods like obfuscation and staged payload delivery to evade code reviews. Techniques include embedding base64-encoded URLs in .env files and using a "trigger" function to fetch remote content, with custom error handling to execute attacker-controlled code.

Most malware payloads are hosted off-platform on services such as Vercel or attacker-controlled domains, with GitLab projects acting as loaders. In 2025, GitLab banned 131 accounts associated with these malicious activities. These accounts displayed diverse infrastructure and malware variants.

Most malware payloads are hosted off-platform on services such as Vercel or attacker-controlled domains, with GitLab projects acting as loaders.
Peter Collins · Thehackingpost

One identified cell, led by North Korean national Kil-Nam Kang, generated over US$1.64 million from freelance work under false identities, operating from Beijing. The cell maintained detailed records, including financial and personnel data, demonstrating an organized revenue operation. Another group developed synthetic identities using technologies like faceswapper.ai to access private codebases and generate fake passports.

North Korean malware activity on GitLab surged in the latter half of 2025, with an average of 11 accounts per month banned. The actors employed anti-analysis techniques, including sandbox checks and malicious npm dependencies, to conceal payload delivery. The use of AI tools like ChatGPT to refine obfuscation techniques was also observed.

Advertisement

Organizations are advised to be cautious of interview-related coding projects and unsolicited test repositories, particularly in sectors like finance and real estate. Strengthening identity verification, monitoring anomalous code platform usage, and assessing the origins of logins can aid in detecting fraudulent IT workers and preventing data breaches.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories