PULSE NAME
Beyond the Backdoor: How Contagious Interview Is Surgically Tampering with MetaMask Wallets.
WHITE PetrP.73 2026-02-19 Modified: 2026-03-21
37
IOCs
MEDIUM VOLUME
The Contagious Interview campaign, linked to North Korean threat actors, is currently targeting IT professionals in the cryptocurrency, Web3, and AI sectors, with the intent to steal financial information and sensitive data. This threat employs a two-stage attack that starts with a JavaScript payload, confirming successful infection by sending a beacon to the attackers' command-and-control (C2) servers, and retrieving additional scripts. These secondary payloads include a Python-based malware named InvisibleFerret and two JavaScript files: one to create a remote-access backdoor and another to identify and exfiltrate sensitive files from the victim's system.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
InvisibleFerret
Indicators of Compromise (1 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 ba5c684d5d611af8d2ec318b66861465122a6fa2494c1ef343769e14a8b144f3 SHA256 of 1b39dfc0ef262baba95b58e3b8d81c8e 2026-02-19