Hackers from North Korea and associated with the Contagious Interview are linked to a previously undisclosed backdoor called AkdoorTea, along with tools such as TsunamiKit and Tropidoor.
See also: New backdoor attacks tech and legal sectors

Slovakian cybersecurity firm ESET, which is tracking the activity under the name DeceptiveDevelopment, said the campaign targets software developers across operating systems—Windows, Linux, and macOS—particularly those working on cryptocurrency and Web3 projects. It is also listed as DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, UNC5342, and Void Dokkaebi.
The campaign involves fake job applications that offer seemingly attractive jobs through platforms such as LinkedIn, Upwork, Freelancer, and Crypto Jobs List. After the initial approach, if the target candidate expresses interest in the opportunity, they are asked to either complete a video assessment by clicking on a link or a coding exercise. The coding exercise requires them to clone projects hosted on GitHub, which silently install malware.
Websites created for video rating display non-existent errors related to camera or microphone access and prompt them to follow ClickFix-style instructions to fix the problem by launching the command prompt or Terminal, depending on the operating system being used. The attacks have generally been found to deliver various pieces of malware such as BeaverTail, InvisibleFerret, OtterCookie, GolangGhost (also known as FlexibleFerret or WeaselStore), and PylangGhost.
See also: New YiBackdoor allows sensitive data extraction

Also deployed as part of these infection sequences are TsunamiKit, PostNapTea, and Tropidoor, the former of which is a malware kit delivered by InvisibleFerret and designed to steal information and cryptocurrency. The use of TsunamiKit was first discovered in November 2024. The kit consists of several components, starting with the TsunamiLoader that triggers the execution of an injector (TsunamiInjector), which drops the TsunamiInstaller and TsunamiHardener.
While TsunamiInstaller acts as a launcher for TsunamiClientInstaller which then downloads and executes TsunamiClient, TsunamiHardener is responsible for setting up persistence for TsunamiClient and configuring Microsoft Defender exceptions. TsunamiClient is the basic model that embeds a spyware in .NET and drops crypto miners like XMRig and NBMiner.
It is believed that TsunamiKit is likely a modification of a dark web project rather than an indigenous creation of the malicious agent, as samples related to the kit have been discovered since December 2021, predating the launch of Contagious Interview, which is believed to have started sometime in late 2022. The BeaverTail stealer and downloader has also been found to act as a distribution vehicle for another malware known as Tropidoor which, according to ASEC, overlaps with a Lazarus Group tool called LightlessCan.
See also: Russian Gamaredon and Turla install Kazuar Backdoor in Ukraine

ESET found evidence of Tropidoor objects uploaded to VirusTotal from Kenya, Colombia, and Canada, adding that the malware also shares “large chunks of code” with PostNapTea, a malware used by the threat actor.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
