24 May 2025

North Korean Lazarus Group Exploits Online Interviews

North Korean hackers are using fake jobs to steal passwords and cryptocurrencies - The Coinomist

The North Korean Lazarus group leverages fake tech job listings to extract cryptocurrency wallets.

According to a new report from Silent Push, Contagious Interview—an affiliate of North Korean Lazarus Group—is behind the creation of three shell companies used to execute targeted campaigns aimed at stealing private credentials and cryptocurrency.

The attack vector centers on bogus recruitment processes conducted by fake entities—BlockNovas LLC, Angeloper Agency, and SoftGlide LLC. These actors list positions on developer-focused platforms such as GitHub and curated job boards, then direct candidates to submit a short video pitch via a bespoke app, which serves as a trojan delivery mechanism.

Midway through the video task, users are hit with a fake error and told to run a command to “resolve it.” But this so-called fix secretly triggers the download of malware, masked as a routine system tool. It’s a textbook case of social engineering—and an effective one. People tend to trust and follow instructions, especially when interacting with a new digital environment.

On-screen prompt that initiates script execution during recording - The Coinomist
Screenshot of a deceptive pop-up displayed mid-recording of a video presentation. Source: Silent Push threat report.

During their investigation, Silent Push analysts identified three types of malware, each tailored to different user platforms (Windows, MacOS, Linux):

  • BeaverTail – collects sensitive information and installs additional payloads.
  • InvisibleFerret – monitors clipboard activity to intercept cryptocurrency wallet private keys.
  • OtterCookie – harvests user credentials, including those stored in browsers.

Crafting an illusion of legitimacy, cybercriminals weave together stolen photographs and AI-spun portraits. The report reveals that even authentic images were artfully retouched using Remaker AI, blurring the line between real and counterfeit.

Presented with convincing corporate façades, users rarely pause to question the reality behind the glass.

Сheck this out: 2024 Crypto Hacks Total $2.2 Billion in Losses

The malicious campaign, now active for over a year, has resulted in significant losses across the Web3 community. Among the recorded incidents, one involved the compromise of a MetaMask wallet’s private key, affecting a standard Web3 developer.

Cyber threat intelligence expert Zach Edwards characterizes this campaign as one of Lazarus Group’s most intricate operations yet:

This certainly isn’t the first Contagious Interview campaign, and it won’t be the last – but it’s by far the most sophisticated and what they’ve done here should set off countless warning bells for anyone targeted by any of the North Korean threat groups.

The North Korean Lazarus Group and its offshoots remain among the most relentless forces in North Korea’s cyber arsenal. Their suspected fingerprints are all over some of the largest crypto heists on record: $1.5 billion stolen from Bybit, $600 million siphoned from Ronin’s blockchain.

Their recent campaigns show a sophisticated blend of technical exploits, social engineering, and diversified attack methods, aimed squarely at IT professionals across industries.

Read on: WhiteBIT’s Cybersecurity Tips

Following enforcement action, the FBI has seized the domain linked to BlockNovas, while websites for SoftGlide and Angeloper Agency remain accessible. Silent Push experts emphasize that advancements in AI are likely to increase the frequency and sophistication of these operations, with threat actors demonstrating rapid adaptability to security measures.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Major U.S. Banks, Including JPMorgan, Discuss Joint Stablecoin Launch — WSJ

Major U.S. Banks, Including JPMorgan, Discuss Joint Stablecoin Launch — WSJ

JPMorgan, Bank of America, Citigroup, and Wells Fargo are in early discussions to develop a joint stablecoin, working through The Clearing House and Zelle amid the advancement of the GENIUS Act.

Dmytro Psevdonimenko
Jupiter Launches Jupiter Lend on Solana in Partnership with Fluid

Jupiter Launches Jupiter Lend on Solana in Partnership with Fluid

Jupiter steps into the DeFi lending space with Fluid, offering up to 90% LTV and fees starting at just 0.1%.

Dmytro Psevdonimenko
Global Sting Busts Darknet Markets, Nets $200M in Seized Digital Assets

Global Sting Busts Darknet Markets, Nets $200M in Seized Digital Assets

On May 22, 2025, the U.S. DOJ announced global operation RapTor targeting darknet trafficking. The raid resulted in 270 arrests, $200 million seized, and over two tons of drugs confiscated.

Vlad Vovk
DOGE Goes Native on Solana — Powered by Wormhole

DOGE Goes Native on Solana — Powered by Wormhole

Thanks to Wormhole, DOGE will be integrated as a true native asset on Solana, skipping the usual wrapped token approach.

Anton Kryshtal
Lyn Alden vs the System: A New Philosophy of Money

Lyn Alden vs the System: A New Philosophy of Money

She avoids hype, doesn’t promise miracles, and refuses to trade on fear—yet Wall Street reads her. Who is Lyn Alden, and why are her ideas challenging the foundations of modern finance?

Iaroslava Kramarenko
Sergey Nazarov (Chainlink): The Man Who Wants to Chain the World Together

Sergey Nazarov (Chainlink): The Man Who Wants to Chain the World Together

How Sergey Nazarov built the rails for a global internet of contracts — and why 2025 might be the year it all locks in.

Elina Moskovchuk
Monica Long: How Ripple’s Quiet Force Is Redrawing Crypto’s Map

Monica Long: How Ripple’s Quiet Force Is Redrawing Crypto’s Map

Ripple’s Monica Long isn’t chasing headlines—she’s quietly building crypto’s future. From payments to tokenization, here’s how she’s reshaping finance from the inside.

Elina Moskovchuk
What Are Altcoins and How Do They Differ from Bitcoin?

What Are Altcoins and How Do They Differ from Bitcoin?

In the early days of crypto, Bitcoin stood alone as a digital asset. But as interest in blockchain deepened, so did the desire to improve, and diversify. This exploration gave rise to altcoins.

The Coinomist
Ripple On-Demand Liquidity: Solutions to Fixing DeFi Slippage

Ripple On-Demand Liquidity: Solutions to Fixing DeFi Slippage

Ripple’s On-Demand Liquidity (ODL) is redefining cross-border transactions. Instead of slow, intermediary-heavy transfers, ODL enables near-instant payments powered by the XRP token.

Vlad Vovk
Resistance levels: logic, methods, techniques

Resistance levels: logic, methods, techniques

Resistance levels are places where price struggles to move higher, often stalling or reversing after several attempts. Let’s learn how to find, draw and interact with them when trading.

The Coinomist
What Is Bitcoin Knots, a Fork by Luke Dashjr?

What Is Bitcoin Knots, a Fork by Luke Dashjr?

Bitcoin Knots (formerly Bitcoin LJR) is an alternative to Bitcoin Core, both allowing network participants to interact with the Bitcoin blockchain.

Anahit Avetisyan
How to Buy New Crypto Before Listing: A Step-by-Step Guide

How to Buy New Crypto Before Listing: A Step-by-Step Guide

Buying a cryptocurrency before it’s listed publicly has become one of the most talked-about strategies in the space, offering the potential for major upside—if done carefully.

The Coinomist
The Rise and Fall of Web3 Darlings: A Guide to Crypto Longevity

The Rise and Fall of Web3 Darlings: A Guide to Crypto Longevity

Most Web3 projects don’t collapse—they just stop being talked about. What makes one protocol a star and another a ghost? And why, in crypto, silence might signal transformation rather than failure?

Vlad Vovk
Bitcoin Retreats from ATH, But Shows No Sign of Investor Exit

Bitcoin Retreats from ATH, But Shows No Sign of Investor Exit

Bitcoin price down to $108,500 after hitting an all-time high, but open interest in futures keeps growing. Profit-taking activity is also muted — just half of what we saw at previous ATH.

Anton Kryshtal
Crypto Market Rotation: HYPE, SPX, and TAO Outperform as Altcoin Momentum Builds

Crypto Market Rotation: HYPE, SPX, and TAO Outperform as Altcoin Momentum Builds

Altcoins are gaining momentum as Bitcoin hits a new all-time high. Our spotlight falls on three standout tokens: HYPE, SPX, and WLD.

Vlad Vovk
MORE
Networking in Crypto: How It Really Works

Networking in Crypto: How It Really Works

In the crypto world, the most valuable connections aren’t made in interviews—they’re formed in the hallways of events and across social platforms. Here, it’s not about business cards. It’s about ideas, engagement, and reputation.

Iaroslava Kramarenko
Earning by Habit: How Crypto Weaves into Everyday Actions

Earning by Habit: How Crypto Weaves into Everyday Actions

You can now earn crypto tokens for your most routine daily habits — shopping, working out, or grabbing breakfast at a café. But how does it actually work?

Yara Zornell
MORE