North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures
## Cybersecurity: North Korean Hacking Campaigns
Cybersecurity: North Korean Hacking Campaigns
North Korean state-sponsored hackers are executing large-scale campaigns that exploit IT hiring processes to deploy JavaScript-based malware, steal code and credentials, and generate covert revenue. These operations involve impersonating recruiters and hiring managers, particularly targeting software developers to run compromised code during technical interviews.
The "Contagious Interview" campaign involves candidates being asked to clone repositories or debug projects that contain malware loaders such as BeaverTail and Ottercookie. When executed, these projects can extract credentials, steal source code, and provide remote control over systems, affecting Windows, Linux, and macOS platforms.
According to GitLab's 2025 threat intelligence, attackers use JavaScript-based codebases and loaders, employing methods like obfuscation and staged payload delivery to evade code reviews. Techniques include embedding base64-encoded URLs in .env files and using a "trigger" function to fetch remote content, with custom error handling to execute attacker-controlled code.
Most malware payloads are hosted off-platform on services such as Vercel or attacker-controlled domains, with GitLab projects acting as loaders. In 2025, GitLab banned 131 accounts associated with these malicious activities. These accounts displayed diverse infrastructure and malware variants.
Most malware payloads are hosted off-platform on services such as Vercel or attacker-controlled domains, with GitLab projects acting as loaders.
One identified cell, led by North Korean national Kil-Nam Kang, generated over US$1.64 million from freelance work under false identities, operating from Beijing. The cell maintained detailed records, including financial and personnel data, demonstrating an organized revenue operation. Another group developed synthetic identities using technologies like faceswapper.ai to access private codebases and generate fake passports.
North Korean malware activity on GitLab surged in the latter half of 2025, with an average of 11 accounts per month banned. The actors employed anti-analysis techniques, including sandbox checks and malicious npm dependencies, to conceal payload delivery. The use of AI tools like ChatGPT to refine obfuscation techniques was also observed.
Organizations are advised to be cautious of interview-related coding projects and unsolicited test repositories, particularly in sectors like finance and real estate. Strengthening identity verification, monitoring anomalous code platform usage, and assessing the origins of logins can aid in detecting fraudulent IT workers and preventing data breaches.
Based on reporting by GBHackers.
