Contagious Interview: Malware delivered through fake developer job interviews
2026-03-12T02:52:20Z•3eb049b461f484120e9e200f2f6a2c54fb277d9920ee59e179877b1a8c6151ea
AI-as-tradecraftAiTMFlexibleFerretLLM-data-exposureNext.jsOAuth-redirection-abuseOtterCookieRCE-to-C2RMMTycoon2FAbackdoorcloud-credentialscredential-theftcrypto-theftdeveloper-targetingmalicious-browser-extensionsnorth-korean-actorsphishingrecruitment-malwaresigned-malwaresource-code-exfiltrationstolen-ev-certificatesupply-chain
What happened
Microsoft Security Blog posts describe multiple high-impact campaigns and trends targeting developers, enterprises, and AI users: the “Contagious Interview” campaign uses fake developer job interviews to deliver backdoors (OtterCookie, FlexibleFerret) that steal API tokens, cloud credentials, crypto wallets, and source code; malicious browser AI assistant/extensions (nearly 900k installs) harvest LLM chat histories and browsing data across thousands of enterprise tenants; Tycoon2FA is a large-scale AiTM phishing/PhaaS operation; signed malware using stolen EV certificates deploys legitimate RM
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 3eb049b461f484120e9e200f2f6a2c54fb277d9920ee59e179877b1a8c6151ea
- Enrichment time
- 2026-03-12T02:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.