North Korean PurpleBravo Campaign Targeted 3,136 IP Addresses via Fake Job Interviews
嗯,用户让我帮忙总结这篇文章,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我得仔细阅读这篇文章,理解它的主要内容。 文章主要讲的是一个名为Contagious Interview的网络间谍活动,涉及朝鲜黑客组织PurpleBravo。他们通过虚假的招聘信息和恶意软件攻击了多个行业的公司,包括人工智能、加密货币、金融服务等。攻击目标主要集中在南亚和北美地区,受害者分布在欧洲、南亚、中东和中美洲的多个国家。 接下来,我需要提取关键信息:攻击者是谁(PurpleBravo),他们的方法(虚假招聘和恶意软件),影响范围(多个行业和地区),以及潜在风险(供应链漏洞)。然后把这些信息浓缩成大约100字。 要注意不要使用“文章内容总结”这样的开头,直接描述内容。同时要确保信息准确且简洁。可能需要调整句子结构,使其更紧凑。 最后检查一下字数,确保不超过限制。这样用户就能快速了解文章的主要内容了。 </think> 朝鲜黑客组织PurpleBravo通过虚假招聘和恶意软件攻击全球20家AI、金融等行业的公司,涉及3136个IP地址。攻击者利用可信开发流程分发恶意软件,并通过VPN隐藏身份。此活动与另一IT工人威胁Wagemole有重叠,凸显供应链安全风险。 2026-1-21 17:17:0 Author: thehackernews.com(查看原文) 阅读量:1 收藏

Cyber Espionage / Malware

As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development sectors in Europe, South Asia, the Middle East, and Central America.

The new findings come from Recorded Future's Insikt Group, which is tracking the North Korean threat activity cluster under the moniker PurpleBravo. First documented in late 2023, the campaign is also known as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.

The 3,136 individual IP addresses, primarily concentrated around South Asia and North America, are assessed to have been targeted by the adversary from August 2024 to September 2025. The 20 victim companies are said to be based in Belgium, Bulgaria, Costa Rica, India, Italy, the Netherlands, Pakistan, Romania, the United Arab Emirates (U.A.E.), and Vietnam.

Cybersecurity

"In several cases, it is likely that job-seeking candidates executed malicious code on corporate devices, creating organizational exposure beyond the individual target," the threat intelligence firm said in a new report shared with The Hacker News.

The disclosure comes a day after Jamf Threat Labs detailed a significant iteration of the Contagious Interview campaign wherein the attackers abuse malicious Microsoft Visual Studio Code (VS Code) projects as an attack vector to distribute a backdoor, underscoring continued exploitation of trusted developer workflows to achieve their twin goals of cyber espionage and financial theft.

The Mastercard-owned company said it detected four LinkedIn personas potentially associated with PurpleBravo that masqueraded as developers and recruiters and claimed to be from the Ukrainian city of Odesa, along with several malicious GitHub repositories that are designed to deliver known malware families like BeaverTail.

PurpleBravo has also been observed managing two distinct sets of command-and-control (C2) servers for BeaverTail, a JavaScript infostealer and loader, and a Go-based backdoor known as GolangGhost (aka FlexibleFerret or WeaselStore) that is based on the HackBrowserData open-source tool.

The C2 servers, hosted across 17 different providers, are administered via Astrill VPN and from IP ranges in China. North Korean threat actors' use of Astrill VPN in cyber attacks has been well-documented over the years.

It's worth pointing out that Contagious Interview complements a second, separate campaign referred to as Wagemole (aka PurpleDelta), where IT workers from the Hermit Kingdom actors seek unauthorized employment under fraudulent or stolen identities with organizations based in the U.S. and other parts of the world for both financial gain and espionage.

Cybersecurity

While the two clusters are treated as disparate sets of activities, there are significant tactical and infrastructure overlaps between them despite the fact that the IT worker threat has been ongoing since 2017.

"This includes a likely PurpleBravo operator displaying activity consistent with North Korean IT worker behavior, IP addresses in Russia linked to North Korean IT workers communicating with PurpleBravo C2 servers, and administration traffic from the same Astrill VPN IP address associated with PurpleDelta activity," Recorded Future said.

To make matters worse, candidates who are approached by PurpleBravo with fictitious job offers have been found to take the coding assessment on company-issued devices, effectively compromising their employers in the process. This highlights that the IT software supply chain is "just as vulnerable" to infiltration from North Korean adversaries other than the IT workers.

"Many of these [potential victim] organizations advertise large customer bases, presenting an acute supply-chain risk to companies outsourcing work in these regions," the company noted. "While the North Korean IT worker employment threat has been widely publicized, the PurpleBravo supply-chain risk deserves equal attention so organizations can prepare, defend, and prevent sensitive data leakage to North Korean threat actors."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/01/north-korean-purplebravo-campaign.html
如有侵权请联系:admin#unsafe.sh