Contagious Interview: Malware delivered through fake developer job interviews

2026-03-12T14:52:17Z6ffdfa9f7f41540ce2df8310b5fb6596ae1cc00c467e8aded6fac30185c46366
AiTMFlexibleFerretLLM-data-exposureOtterCookieRMM-backdoorsTycoon2FAapi-tokenscloud-credentialscredential-theftcrypto-wallet-theftdeveloper-targetingjob-interview-scammalicious-browser-extensionsnext.js-malicious-reposoauth-redirection-abusephishing-as-a-servicesource-code-exfiltrationstolen-ev-certificatessupply-chainthreat-modeling-ai

What happened

Feed of Microsoft Security Blog posts describing multiple high-risk campaigns and threats targeting developers and enterprises. Key item: “Contagious Interview” campaign uses fake developer job interviews to deliver backdoors (OtterCookie, FlexibleFerret) that steal API tokens, cloud credentials, crypto wallets, and source code. Other notable activity includes malicious AI browser extensions harvesting LLM chat histories at scale, Tycoon2FA AiTM phishing-as-a-service at large scale, signed malware using stolen EV certificates to deploy RMM backdoors, OAuth redirection abuse for phishing/malwar

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
6ffdfa9f7f41540ce2df8310b5fb6596ae1cc00c467e8aded6fac30185c46366
Enrichment time
2026-03-12T14:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Contagious Interview: Malware delivered through fake developer job interviews · Baitaphish