HomeSecurityChollima ATP attacks job seekers

Chollima ATP attacks job seekers

The Chollima ATP group , linked to North Korea, has emerged as a sophisticated threat actor, organizing targeted campaigns against job seekers and organizations through deceptive recruitment processes.

See also: US: Woman jailed for helping North Koreans break into companies

Chollima ATP

Active since December 2022, this advanced persistent threat has developed a sophisticated, multi-stage attack methodology that exploits the trust that exists in professional networking and job search activities.

The group's operations represent a significant evolution in social engineering tactics, exploiting the vulnerability of individuals seeking employment opportunities to establish positions within targeted organizations.

The campaign demonstrates remarkable sophistication in its approach, beginning with attackers pretending to be legitimate employees or hiring managers inviting potential victims to participate in online interviews.

During these seemingly authentic interactions conducted via video conferencing platforms, threat actors skillfully manipulate targets into downloading and installing malicious NPM packages hosted on GitHub repositories.

Attackers present these packages as legitimate software that requires technical evaluation or code review, effectively weaponizing standard software development interview practices.

Abdulrehman Ali identified the complex infection chain of Chollima ATP, noting that the group strategically targets software developers and IT professionals who possess both technical expertise and potential access to sensitive organizational resources.

See also: Treasury imposes sanctions on North Korea

The campaign's effectiveness comes from exploiting two key demographic vulnerabilities: recently laid-off employees who may retain access credentials to their former employers, and active professionals seeking freelance work opportunities alongside their primary employment.

Chollima ATP attacks job seekers

The delivery mechanism represents a sophisticated abuse of GitHub's trusted infrastructure, turning the platform into an unintended network for distributing malicious payloads. Attackers create repositories containing NPM packages embedded with malicious JavaScript code designed to deploy the InvisibleFerret.

This Python-based malware establishes persistent command communication over TCP connections secured with XOR encryption, allowing remote access and credential harvesting capabilities.

The Chollima ATP group's infection process begins with the execution of the malicious NPM package, which triggers a carefully orchestrated deployment sequence. Once installed, the JavaScript payload executes system identification commands and prepares the environment for the installation of the secondary Python backdoor.

The InvisibleFerret component takes advantage of the target's existing Python environment, a strategic choice given that most software developers have already installed the necessary dependencies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The backdoor ensures communication with the administration servers via encrypted TCP channels, using XOR encryption with hardcoded keys to falsify data transmission. The malware's interoperability allows operations in Windows, Linux, and macOS environments, maximizing the attack surface across various deployment ecosystems.

Once installed, the backdoor facilitates comprehensive data extraction, including browser credential collection and remote command execution capabilities.

See also: North Korea added new tactics to infiltrate organizations

The success of the Chollima ATP campaign highlights critical vulnerabilities in supply chain security and social engineering defenses, particularly within development communities where interactions on GitHub and technical assessments during interviews are standard practice.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS