Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Operation Contagious Interview, Wagemole, Tenacious Pungsan, Nickel Tapestry, UNC5267, WaterPlum, PurpleBravo, Storm-0287, Jasper Sleet, Famous Chollima, Storm-1877, Void Dokkaebi, NICKEL TAPESTRY, Contagious Interview Actors, North Korean Threat Actors, DPRK Job Lure, CL-STA-0241, Contagious Interview, BlockNovas LLC, Angeloper Agency, SoftGlide LLC, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, UNC5342, TAG-120
A subgroup of Lazarus Group, Hidden Cobra, Labyrinth Chollima . ( Palo Alto ) Unit 42 researchers recently discovered two separate campaigns targeting job-seeking activities linked to state-sponsored threat actors associated with the Democratic People’s Republic of Korea (DPRK), commonly known as North Korea. We call the first campaign “Contagious Interview,” where threat actors pose as employers (often anonymously or with vague identities) to lure software developers into installing malware through the interview process. This malware creates the potential for various types of theft. We attribute with moderate confidence that Contagious Interview is run by a North Korea state-sponsored threat actor. We call the second campaign “Wagemole,” where threat actors seek unauthorized employment with organizations based in the US and other parts of the world, with potential for both financial gain and espionage. We attribute with high confidence that Wagemole is a North Korea state-sponsored threat. Activity from both campaigns remains an ongoing active threat.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database