SYMBOLCOMMON_NAMEaka. SYNONYMS

WageMole  (Back to overview)

aka: Famous Chollima, Nickel Tapestry, PurpleBravo, Storm-1877, UNC5267, Void Dokkaebi, Wagemole, WaterPlum

WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in Western countries, leveraging stolen personal data from the Contagious Interview campaign. Threat actors create fake identities, including passports and driver's licenses, and prepare study guides for interviews, often utilizing generative AI for well-structured responses. They target small to mid-sized businesses and utilize job platforms like Upwork and Indeed, while employing automation scripts for account creation. WageMole's activities include sharing code within their group and requesting payments through platforms like PayPal to conceal their identity.


Associated Families
osx.flexibleferret osx.frostyferret win.tsunamikit osx.golangghost win.golangghost osx.friendlyferret py.invisibleferret py.pylangghost js.jadesnow js.ottercandy js.otter_cookie js.beavertail osx.beavertail win.beavertail win.akdoortea win.tropidoor

References
2026-09-21 ⋅ Atlassian ⋅ Atlassian Trust and Security, Dawid Osojca, Parthiban Rajendran, Ramazan Uysal
From fake interviews to malicious repositories: Disrupting Contagious Interview
BeaverTail BeaverTail Beavertail
2026-09-17 ⋅ OpenSourceMalware ⋅ Paul McCarty
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
BeaverTail OtterCookie BeaverTail Beavertail
2026-09-03 ⋅ Jamf Blog ⋅ Jamf Threat Labs
Contagious Interview steps outside the developer workflow
OtterCookie
2026-08-10 ⋅ sonatype ⋅ Sonatype Research Team
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
JADESNOW
2026-07-29 ⋅ SafeDep ⋅ SafeDep Team
Joyfill npm Packages Compromised with Blockchain C2 Loader
JADESNOW
2026-07-28 ⋅ Socket ⋅ Socket Research Team
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
JADESNOW
2026-07-28 ⋅ StepSecurity ⋅ Varun Sharma
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
JADESNOW
2026-07-17 ⋅ Elastic ⋅ Daniel Stepanic
New North Korean campaign uses fake coding interviews to steal developer credentials
OtterCookie
2026-07-17 ⋅ OpenSourceMalware ⋅ Jenn Gile
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign
JADESNOW
2026-07-15 ⋅ OpenSourceMalware ⋅ Paul McCarty
PolinRider Confirmed Footprint Grows 6.5x Since March
JADESNOW
2026-07-14 ⋅ Checkmarx ⋅ Pavan Gudimalla
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
JADESNOW
2026-07-12 ⋅ OX Security ⋅ Moshe Siman Tov Bustan
Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials
OtterCandy
2026-07-01 ⋅ Socket ⋅ Karlo Zanki
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
JADESNOW
2026-06-30 ⋅ JFrog Security ⋅ Yair Benamou
Lazarus-Linked npm Malware Masquerades as Rollup Polyfills
OtterCookie
2026-06-24 ⋅ JFrog Security ⋅ Guy Korolevski, Yair Benamou
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
JADESNOW
2026-06-22 ⋅ JFrog Security ⋅ Yair Benamou
From PostCSS Masquerading to Windows RAT
PylangGhost
2026-06-22 ⋅ Melted in Hex ⋅ Melted in Hex
Dead Drops on the Blockchain: Reversing a DPRK npm Loader (PolinRider / A6-Shadow-15)
JADESNOW
2026-06-16 ⋅ Checkmarx ⋅ Pavan Gudimalla
ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey
JADESNOW
2026-06-12 ⋅ SafeDep ⋅ SafeDep
astro.config.mjs Supply Chain Attack via Blockchain C2
JADESNOW
2026-05-31 ⋅ Socket ⋅ Kirill Boychenko
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
JADESNOW
2026-05-22 ⋅ Trend Micro ⋅ Kazuki Fujisawa
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
BeaverTail InvisibleFerret
2026-05-05 ⋅ OpenSourceMalware ⋅ OpenSourceMalware
Lazarus Group Uses Git Hooks To Hide Malware
BeaverTail InvisibleFerret
2026-05-05 ⋅ Red Asgard ⋅ Red Asgard
Hunting Lazarus Part VII: The Server That Was Not Just FTP
BeaverTail OtterCookie
2026-05-01 ⋅ kmsec ⋅ Kieran Miyamoto
North Korea's abuse of Cloudflare Workers and Pages
PylangGhost
2026-04-22 ⋅ Expel ⋅ Marcus Hutchins
Inside Lazarus: How North Korea uses AI to industrialize attacks on developers
BeaverTail OtterCookie InvisibleFerret HexagonalRodent
2026-04-21 ⋅ Trend Micro ⋅ Lucas Silva
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
BeaverTail JADESNOW OtterCookie InvisibleFerret
2026-04-03 ⋅ Casco ⋅ Rene Brandel
The Blueprint of a North Korean Attack on Open-Source
JADESNOW
2026-04-03 ⋅ Panther ⋅ Michael Baker
jsonspack: Multi-Tenant Node.js RAT — DPRK Supply Chain Campaign
OtterCookie
2026-03-23 ⋅ Sophos ⋅ Sophos Counter Threat Unit Research Team
NICKEL ALLEY strategy: Fake it ‘til you make it
PylangGhost GolangGhost Nickel Alley
2026-03-13 ⋅ kmsec ⋅ Kieran Miyamoto
First instance of PylangGhost RAT observed on npm
PylangGhost
2026-03-11 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Defender Security Research Team
Contagious Interview: Malware delivered through fake developer job interviews
BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview
2026-03-09 ⋅ Abstract Security ⋅ Abstract Security Threat Research Organization (ASTRO)
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains Part 2
GolangGhost PylangGhost GolangGhost
2026-03-07 ⋅ OpenSourceMalware ⋅ OpenSourceMalware
PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos
JADESNOW
2026-03-06 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
AI as tradecraft: How threat actors operationalize AI
OtterCookie
2026-03-05 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
JADESNOW
2026-02-25 ⋅ Abstract Security ⋅ Abstract Security Threat Research Organization (ASTRO)
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1
BeaverTail PylangGhost GolangGhost
2026-02-19 ⋅ GitLab ⋅ Oliver Smith
GitLab Threat Intelligence Team reveals North Korean tradecraft
BeaverTail OtterCookie Contagious Interview
2026-01-20 ⋅ Abstract Security ⋅ Abstract Security Threat Research Organization
Contagious Interview: Tracking the VS Code Tasks Infection Vector
BeaverTail InvisibleFerret
2026-01-19 ⋅ OpenSourceMalware ⋅ Paul McCarty
Contagious Interview gets an upgrade for 2026 - A comprehensive analysis by OpenSourceMalware
OtterCandy
2026-01-13 ⋅ Security Alliance ⋅ Security Alliance
VS Code Tasks Abuse by Contagious Interview (DPRK)
BeaverTail InvisibleFerret
2026-01-13 ⋅ Medium @0xOZ ⋅ OZ
How to Get Scammed (by DPRK Hackers)
JADESNOW
2026-01-11 ⋅ Red Asgard ⋅ Red Asgard
Hunting Lazarus: Inside the Contagious Interview C2 Infrastructure
BeaverTail InvisibleFerret
2025-12-17 ⋅ Recorded Future ⋅ Insikt Group
PurpleBravo’s Targeting of the IT Software Supply Chain
BeaverTail InvisibleFerret PylangGhost GolangGhost
2025-12-17 ⋅ Crystal Intelligence ⋅ Crystal Intelligence
How we proved North Korea’s blockchain malware campaign
JADESNOW
2025-12-08 ⋅ Ransom-ISAC ⋅ Andrii Sovershennyi, Nick Smart
Cross-Chain TxDataHiding Crypto Heist: A Very (Very) Chainful Process (Part 4)
JADESNOW
2025-11-28 ⋅ OpenSourceMalware ⋅ OpenSourceMalware
"Contagious Interview" campaign abuses Microsoft VSCode tasks to drop malware and gain persistence
BeaverTail InvisibleFerret
2025-11-13 ⋅ NVISO Labs ⋅ Bart Parys, Efstratios Lontzetidis, Stef Collart
Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery
BeaverTail OtterCookie InvisibleFerret Beavertail TsunamiKit
2025-11-13 ⋅ Ransom-ISAC ⋅ Yashraj Solanki
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 3)
JADESNOW
2025-10-27 ⋅ Ransom-ISAC ⋅ Ellis Stannard
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 2)
JADESNOW
2025-10-20 ⋅ Ransom-ISAC ⋅ Ellis Stannard
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 1)
JADESNOW
2025-10-20 ⋅ Medium Deriv-Tech ⋅ Shantanu Ghumade
How a fake AI recruiter delivers five staged malware disguised as a dream job
BeaverTail OtterCookie InvisibleFerret
2025-10-16 ⋅ Mandiant ⋅ Blas Kojusner, Joseph Dobson, Robert Wallace
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
JADESNOW UNC5342
2025-10-16 ⋅ Cisco Talos ⋅ Michael Kelley, Vanja Svajcer
BeaverTail and OtterCookie evolve with a new Javascript module
BeaverTail OtterCookie InvisibleFerret
2025-10-15 ⋅ NTT ⋅ Rintaro Koike
OtterCandy, malware used by WaterPlum
OtterCandy
2025-10-15 ⋅ David Dodda ⋅ Dvaid Dodda
How I Almost Got Hacked By A 'Job Interview'
OtterCookie
2025-10-10 ⋅ Socket ⋅ Kirill Boychenko
North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads
BeaverTail InvisibleFerret
2025-10-06 ⋅ BlackPoint ⋅ Caden Toellner, Nevan Beal, Sam Decker
Malicious Node Package Deploys OtterCookie
OtterCookie
2025-09-30 ⋅ kuxhagra ⋅ Kushagra Sarathe
that one time i got hacked: a security incident breakdown
JADESNOW
2025-09-25 ⋅ Virus Bulletin ⋅ Matěj Havránek, Peter Kálnai
DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception
BeaverTail OtterCookie InvisibleFerret PylangGhost AkdoorTea GolangGhost Tropidoor TsunamiKit
2025-09-25 ⋅ ESET Research ⋅ Matěj Havránek, Peter Kálnai
DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception
BeaverTail OtterCookie InvisibleFerret PylangGhost AkdoorTea GolangGhost Tropidoor TsunamiKit
2025-09-17 ⋅ GitLab ⋅ GitLab
Tech Note - BeaverTail variant distributed via malicious repositories and ClickFix lure
BeaverTail OtterCookie BeaverTail InvisibleFerret Beavertail GolangGhost
2025-09-10 ⋅ ANY.RUN ⋅ ANY.RUN
Lazarus Group Attacks in 2025: Here’s Everything SOC Teams Need to Know
OtterCookie InvisibleFerret PylangGhost
2025-08-27 ⋅ Anthropic ⋅ Anthropic
Anthropic - Threat Intelligence Report: August 2025
BeaverTail OtterCookie GolangGhost InvisibleFerret GolangGhost
2025-08-11 ⋅ nimanthadeshappriya.com ⋅ Nimantha Deshappriya
From Colombo to Pyongyang
BeaverTail BeaverTail Beavertail
2025-08-06 ⋅ ANY.RUN ⋅ Mauro Eldritch
PyLangGhost RAT: Rising Stealer from Lazarus Group Striking Finance and Technology
PylangGhost GolangGhost
2025-07-30 ⋅ GBHackers on Security ⋅ Lucas Mancilha
Lazarus Group enhances malware delivery by using new techniques
OtterCookie
2025-07-28 ⋅ Wiz.io ⋅ Merav Bar
TraderTraitor: Deep Dive
GolangGhost Manuscrypt RN Stealer DRATzarus GolangGhost PostNapTea Volgmer wAgentTea
2025-07-14 ⋅ Socket ⋅ Kirill Boychenko
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
BeaverTail InvisibleFerret
2025-06-24 ⋅ Socket ⋅ Socket
Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages
BeaverTail InvisibleFerret
2025-06-23 ⋅ PolySwarm Tech Team ⋅ The Hivemind
Famous Chollima’s PylangGhost
GolangGhost PylangGhost GolangGhost
2025-06-18 ⋅ Cisco Talos ⋅ Vanja Svajcer
Famous Chollima deploying Python version of GolangGhost RAT
GolangGhost PylangGhost GolangGhost
2025-06-12 ⋅ Aikido ⋅ Charlie Eriksen
A deeper look into the threat actor behind the react-native-aria attack
JADESNOW
2025-06-06 ⋅ Aikido ⋅ Charlie Eriksen
RATatouille: A Malicious Recipe Hidden in rand-user-agent (Supply Chain Compromise)
JADESNOW
2025-06-03 ⋅ ANY.RUN ⋅ ANY.RUN
OtterCookie: Analysis of Lazarus Group Malware Targeting Finance and Tech Professionals
BeaverTail OtterCookie InvisibleFerret
2025-05-12 ⋅ ESET Research ⋅ ESET Research
ESET APT Activity Report Q4 2024–Q1 2025
BeaverTail InvisibleFerret GolangGhost
2025-05-08 ⋅ NTT Security ⋅ Masaya Motoda, Rintaro Koike
Additional Features of OtterCookie Malware Used by WaterPlum
OtterCookie WageMole
2025-05-07 ⋅ NTT Security ⋅ Masaya Motoda, Rintaro Koike
Additional Features of OtterCookie Malware Used by WaterPlum
BeaverTail OtterCookie InvisibleFerret
2025-04-25 ⋅ HiSolutions ⋅ Maik Würth, Mateo Mrvelj, Nicolas Sprenger
Rolling in the Deep(Web): Lazarus Tsunami
InvisibleFerret tsunami TsunamiKit
2025-04-24 ⋅ Silent Push ⋅ Silent Push
Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
BeaverTail OtterCookie FrostyFerret GolangGhost InvisibleFerret GolangGhost
2025-04-23 ⋅ Trend Micro ⋅ Feike Hacquebord, Stephen Hilt
Russian Infrastructure Plays Crucial Role in North Korean Cybercrime Operations
BeaverTail FrostyFerret GolangGhost InvisibleFerret GolangGhost WageMole
2025-04-11 ⋅ Bitso Quetzal Team ⋅ Mauro Eldritch
Interview with the Chollima
BeaverTail OtterCookie InvisibleFerret
2025-04-04 ⋅ Socket ⋅ Socket
Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads
BeaverTail InvisibleFerret
2025-04-04 ⋅ Cyber and Ramen ⋅ Cyber and Ramen
OtterCookie Expands Targeting to AI Coding Tools: Analysis of a Trojanized npm Campaign
OtterCookie
2025-04-02 ⋅ ASEC ⋅ ASEC
BeaverTail and Tropidoor Malware Distributed via Recruitment Emails
BeaverTail Tropidoor
2025-03-31 ⋅ Aikido ⋅ Charlie Eriksen
Malware hiding in plain sight: Spying on North Korean Hackers
BeaverTail
2025-03-31 ⋅ Sekoia ⋅ Amaury G., Coline Chavane, Félix Aime, Sekoia TDR
From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic
FrostyFerret GolangGhost GolangGhost
2025-02-20 ⋅ ESET Research ⋅ ESET Research
DeceptiveDevelopment targets freelance developers
BeaverTail InvisibleFerret
2025-02-13 ⋅ Moonlock ⋅ Moonlock
Cybercrooks Are Using Fake Job Listings to Steal Crypto
GolangGhost
2025-02-13 ⋅ Recorded Future ⋅ Recorded Future
Inside the Scam: North Korea’s IT Worker Threat
BeaverTail OtterCookie InvisibleFerret
2025-02-07 ⋅ ⋅ SI-CERT ⋅ SI-CERT
SI-CERT TZ016 / BeaverTail & InvisibleFerret
BeaverTail InvisibleFerret
2025-02-05 ⋅ Bitdefender ⋅ Alina Bizga, Andrei ANTON-AANEI, Ionuț-Alexandru Baltariu
Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam
BeaverTail InvisibleFerret tsunami
2025-02-03 ⋅ SentinelOne ⋅ Phil Stokes, Tom Hegel
macOS FlexibleFerret | Further Variants of DPRK Malware Family Unearthed
FlexibleFerret FriendlyFerret FrostyFerret
2025-01-29 ⋅ Socket ⋅ Kirill Boychenko, Peter van der Zee
North Korean APT Lazarus Targets Developers with Malicious npm Package
BeaverTail InvisibleFerret
2025-01-29 ⋅ SecurityScorecard ⋅ SecurityScorecard STRIKE Team
Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign
BeaverTail InvisibleFerret
2025-01-16 ⋅ NTT Security ⋅ Masaya Motoda, Rintaro Koike, Ryu Hiyoshi
OtterCookie, new malware used in Contagious Interview campaign
OtterCookie
2024-12-24 ⋅ ⋅ NTT Security Holdings ⋅ NTT Security Holdings
Contagious Interview Uses New Malware Otter Cookie
BeaverTail OtterCookie InvisibleFerret
2024-11-26 ⋅ Arxiv ⋅ Alessio Di Santo
Lazarus Group Targets Crypto-Wallets and Financial Data while employing new Tradecrafts
BeaverTail InvisibleFerret tsunami TsunamiKit
2024-11-14 ⋅ Palo Alto ⋅ Unit 42
Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack
BeaverTail InvisibleFerret WageMole
2024-11-14 ⋅ eSentire ⋅ eSentire
Bored BeaverTail & InvisibleFerret Yacht Club – A Lazarus Lure Pt.2
BeaverTail InvisibleFerret
2024-11-04 ⋅ Israel National Cyber Directorate (INCD) ⋅ Israel National Cyber Directorate (INCD)
Deep Drive Analysis of the BeaverTail Infostealer
BeaverTail
2024-11-04 ⋅ Zscaler ⋅ Zscaler
From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West
BeaverTail InvisibleFerret WageMole
2024-10-29 ⋅ ⋅ Macnica ⋅ Hiroshi Takeuchi
Job Offer from the North: Contagious Interview for Software Developers
BeaverTail InvisibleFerret
2024-10-29 ⋅ SecurityScorecard ⋅ SecurityScorecard STRIKE Team
The Job Offer That Wasn’t: How We Stopped an Espionage Plot
BeaverTail InvisibleFerret
2024-10-24 ⋅ Datadog ⋅ Datadog
Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview
BeaverTail InvisibleFerret
2024-10-17 ⋅ Github (ssrdio) ⋅ Gregor Spagnolo
Analysis of BeaverTail & InvisibleFerret activity
BeaverTail InvisibleFerret
2024-10-09 ⋅ Palo Alto ⋅ Unit 42
Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware
BeaverTail Beavertail
2024-09-10 ⋅ Stacklok ⋅ Stacklok
Dependency hijacking: Dissecting North Korea’s new wave of DeFi-themed open source attacks targeting developers
BeaverTail InvisibleFerret
2024-09-04 ⋅ Group-IB ⋅ Sharmine Low
APT Lazarus: Eager Crypto Beavers, Video calls and Games
BeaverTail BeaverTail InvisibleFerret Beavertail
2024-07-31 ⋅ Securonix ⋅ Securonix
Research Update: Threat Actors Behind the DEV#POPPER Campaign Have Retooled and are Continuing to Target Software Developers via Social Engineering
BeaverTail
2024-07-15 ⋅ Objective-See ⋅ Patrick Wardle
This Meeting Should Have Been an Email: A DPRK stealer, dubbed BeaverTail, targets users via a trojanized meeting app
BeaverTail BeaverTail InvisibleFerret
2024-05-10 ⋅ ⋅ Qianxin Threat Intelligence Center ⋅ Threat Intelligence Center
Recruitment trap for blockchain practitioners: Analysis of suspected Lazarus (APT-Q-1) stealing operations
BeaverTail
2024-03-24 ⋅ Securonix ⋅ Securonix
Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors
BeaverTail
2023-11-21 ⋅ Palo Alto Networks Unit 42 ⋅ Unit 42
Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors
BeaverTail InvisibleFerret WageMole

Credits: MISP Project