Contagious Interview: Malware delivered through fake developer job interviews

2026-03-12T02:52:20Z3eb049b461f484120e9e200f2f6a2c54fb277d9920ee59e179877b1a8c6151ea
AI-as-tradecraftAiTMFlexibleFerretLLM-data-exposureNext.jsOAuth-redirection-abuseOtterCookieRCE-to-C2RMMTycoon2FAbackdoorcloud-credentialscredential-theftcrypto-theftdeveloper-targetingmalicious-browser-extensionsnorth-korean-actorsphishingrecruitment-malwaresigned-malwaresource-code-exfiltrationstolen-ev-certificatesupply-chain

What happened

Microsoft Security Blog posts describe multiple high-impact campaigns and trends targeting developers, enterprises, and AI users: the “Contagious Interview” campaign uses fake developer job interviews to deliver backdoors (OtterCookie, FlexibleFerret) that steal API tokens, cloud credentials, crypto wallets, and source code; malicious browser AI assistant/extensions (nearly 900k installs) harvest LLM chat histories and browsing data across thousands of enterprise tenants; Tycoon2FA is a large-scale AiTM phishing/PhaaS operation; signed malware using stolen EV certificates deploys legitimate RM

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
3eb049b461f484120e9e200f2f6a2c54fb277d9920ee59e179877b1a8c6151ea
Enrichment time
2026-03-12T02:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.