North Korean hackers are using a fake video conferencing app, impersonating FreeConference.com, as part of a new malicious campaign being tracked as Contagious Interview.

The attacks were detected by the company Group-IB in mid-August 2024.
The attacks begin with a fake job interview and seekers jobinto downloading and running a Node.js project containing the BeaverTail downloader malware, which in turn delivers the InvisibleFerret backdoor. This malware allows remote access and has keylogging and browser credential theft capabilities.
See also: North Korean hackers distribute FudModule rootkit via Chrome zero-day
Some variants of BeaverTail, which also functions as an information stealer, have manifested in the form of JavaScript malware, usually distributed via fake npm packages, as part of a supposed technical assessment during the interview process.
However, in July 2024, researchers observed the use of Windows MSI installers and Apple macOS disk image (DMG) files disguised as the legitimate MiroTalk video conferencing software, acting as a conduit for the deployment of an updated version of BeaverTail.
The latest findings from Group-IB, which has attributed the campaign to the notorious North Korean hackers Lazarus, suggest that the attackers continue to rely on this distribution mechanism, with the only difference being that the installer (“FCCCall.msi”) now mimics FreeConference .com instead of MiroTalk.
The fake installer is believed to be downloaded from a website called freeconference[.]io, which uses the same registrar as the fake mirotalk[.]net website.
“In addition to Linkedin, Lazarus seeks potential victims on other job search platforms such as WWR, Moonlight, Upwork and others,” said security researcher Sharmine Low. “After initial contact, they would often attempt to move the conversation to Telegram, where they would then ask potential interviewees to download a video conferencing app or a Node.js project to perform a technical task as part of the interview process.”
See also: North Korean hackers target developers with malicious npm packages

Continuous development and improvement of BeaverTail
Researchers have observed that attackers are injecting malicious JavaScript into cryptocurrency-and gaming-related repositories. The JavaScript code, in turn, is designed to retrieve BeaverTail's JavaScript code from the ipcheck[.]cloud or regioncheck[.]net domain.
Additionally, BeaverTail is now configured to extract data from more cryptocurrency wallet extensions such as Kaikas, Rabby, Argent X, and Exodus Web3.
Researchers also observed that BeaverTail's information-stealing capabilities are now carried out through a set of Python scripts, collectively called CivetQ. The malware can steal cookies, browser data, keystrokes, and clipboard content. In total, the malware can target 74 browser extensions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“The malware can steal data from Microsoft Sticky Notes by targeting the application’s SQLite database files located at `%LocalAppData%\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\plum.sqlite,` where the user’s notes are stored in unencrypted format,” Low said.
“By searching and extracting data from this database , the malware can retrieve and steal sensitive information from the victim's Sticky Notes app“.
The expert continued, saying: “The Lazarus group has updated its tactics, upgraded its tools, and found better ways to hide its activities. They show no signs of slowing down, as this campaign targeting job seekers shows. Their attacks are becoming increasingly creative and are now expanding their reach to more platforms.”
See also: South Korean hackers exploit WPS Office vulnerability

North Korean hackers: A major threat
North Korean hackers pose a threat to global security through a series of cyberattacks targeting critical systems and networks. These attacks can cause significant disruption and undermine trust in digital systems.
Additionally, North Korean hackers have demonstrated their ability to infiltrate financial systems, such as banks and cryptocurrencies, causing economic instability.
Finally, they can use their skills to steal sensitive information, such as military secrets or intellectual property, thus causing security issues and political tensions.
Source: thehackernews.com
