BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Use JSON Services for Malware Delivery

North Korean Threat Group Behind Contagious Interview Campaign Uses JSON Storage Services to Deliver Trojanized Malware Targeting Developers on Professional Networks

  • A North Korean group behind the Contagious Interview campaign now uses JSON storage services to host Malware payloads.
  • The attackers lure targets on professional networks to download trojanized code from legitimate repositories.
  • Malware includes JavaScript BeaverTail and a Python backdoor called InvisibleFerret with updated payload delivery.
  • The campaign also employs additional tools like TsunamiKit for system fingerprinting and data theft.
  • Legitimate platforms help the attackers evade detection by blending malicious traffic with normal activity.

Threat actors from North Korea linked to the Contagious Interview campaign have adopted new tactics in late 2025 by using JSON storage services such as JSON Keeper, JSONsilo, and npoint.io to distribute malware payloads. These changes were detailed by researchers Bart Parys, Stef Collart, and Efstratios Lontzetidis, who noted the group’s use of trojanized code projects as a baiting method detailed here.

- Advertisement -

The attackers approach potential victims on professional networking platforms like LinkedIn, posing as collaborators or recruiters conducting job assessments. Targets are then prompted to download demo projects hosted on popular code-sharing sites such as GitHub, GitLab, or Bitbucket. Within these projects, a file named “server/config/.config.env” often contains a disguised Base64-encoded URL linking to JSON storage services where the following-stage malware is hidden in an obfuscated format.

The primary malware identified is a JavaScript strain called BeaverTail, which steals sensitive information. BeaverTail also deploys a Python backdoor named InvisibleFerret. This backdoor remains mostly unchanged from its initial report by Palo Alto Networks in late 2023, except for its new ability to retrieve an additional payload, TsunamiKit, from Pastebin.

Earlier reports from ESET in September 2025 confirmed Contagious Interview’s use of TsunamiKit alongside other tools like Tropidoor and AkdoorTea. TsunamiKit serves functions such as system fingerprinting, data collection, and downloading further payloads from a hardcoded .onion address, which is currently inactive.

Researchers concluded, “It’s clear that the actors behind Contagious Interview are not lagging behind and are trying to cast a very wide net to compromise any (software) developer that might seem interesting to them, resulting in exfiltration of sensitive data and crypto wallet information.” They also highlighted how the usage of legitimate JSON storage platforms and popular code repositories supports the attackers’ goal of remaining stealthy and blending malicious operations with normal network traffic.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fluence Energy Soars as Nvidia’s AI Factory Partner

Fluence Energy soared over 43% after being named the exclusive energy storage partner for...

Radiant Capital to Wind Down After $50M North Korea Hack

Radiant Capital is shutting down its core operations after failing to recover from a...

DuckDuckGo’s No-AI Search Soars After Google AI Pivot

Traffic to DuckDuckGo's AI-free search page tripled immediately after Google's I/O announcement and has...

Tether-backed Twenty One Capital faces NYSE deadline Friday

Tether-controlled Twenty One Capital must fill an independent audit committee seat by Friday to...

Bitcoin Volatility Plummets, Hinting at Big Move

Bitcoin's one-week realized volatility has plunged 56% to 17.2%, well below its long-term median...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading