North Korean threat actors behind the Contagious Interview and WageMole campaigns have refined their tactics, enhancing the obfuscation of their scripts to evade detection. InvisibleFerret now boasts a dynamic RMM configuration and OS-specific persistence mechanisms, while Contagious Interview has expanded its arsenal with macOS applications, targeting a wider victim pool. These attacks have compromised over 100 devices, leading to the theft of sensitive data like source code, cryptocurrency wallets, and personal information. This information is used to create fake identities and secure remote employment in Western countries, facilitated by generative AI.
Source: GBHackers