PULSE NAME
Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets.
WHITE PetrP.73 2026-02-19 Modified: 2026-03-21
37
IOCs
MEDIUM VOLUME
The Contagious Interview campaign, linked to North Korean threat actors, is currently targeting IT professionals in the cryptocurrency, Web3, and AI sectors, with the intent to steal financial information and sensitive data. This threat employs a two-stage attack that starts with a JavaScript payload, confirming successful infection by sending a beacon to the attackers' command-and-control (C2) servers, and retrieving additional scripts. These secondary payloads include a Python-based malware named InvisibleFerret and two JavaScript files: one to create a remote-access backdoor and another to identify and exfiltrate sensitive files from the victim's system.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
InvisibleFerret
Indicators of Compromise (1 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 3606f2a1a44a4c85cde75e52c288a2a779be4acf SHA1 of 1b39dfc0ef262baba95b58e3b8d81c8e 2026-02-19