By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
Computing

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

News Room
Last updated: 2025/11/14 at 1:43 PM
News Room Published 14 November 2025
Share
North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
SHARE

Nov 14, 2025Ravie LakshmananMalware / Threat Intelligence

The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage malicious payloads.

“The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware from trojanized code projects, with the lure,” NVISO researchers Bart Parys, Stef Collart, and Efstratios Lontzetidis said in a Thursday report.

The campaign essentially involves approaching prospective targets on professional networking sites like LinkedIn, either under the pretext of conducting a job assessment or collaborating on a project, as part of which they are instructed to download a demo project hosted on platforms like GitHub, GitLab, or Bitbucket.

In one such project spotted by NVISO, it has been found that a file named “server/config/.config.env” contains a Base64-encoded value that masquerades as an API key, but, in reality, is a URL to a JSON storage service like JSON Keeper where the next-stage payload is stored in obfuscated format.

DFIR Retainer Services

The payload is a JavaScript malware known as BeaverTail, which is capable of harvesting sensitive data and dropping a Python backdoor called InvisibleFerret. While the functionality of the backdoor has remained largely unchanged from when it was first documented by Palo Alto Networks in late 2023, one notable change involves fetching an additional payload dubbed TsunamiKit from Pastebin.

It’s worth noting that use of TsunamiKit as part of the Contagious Interview campaign was highlighted by ESET back in September 2025, with the attacks also dropping Tropidoor and AkdoorTea. The toolkit is capable of system fingerprinting, data collection, and fetching more payloads from a hard-coded .onion address that’s currently offline.

“It’s clear that the actors behind Contagious Interview are not lagging behind and are trying to cast a very wide net to compromise any (software) developer that might seem interesting to them, resulting in exfiltration of sensitive data and crypto wallet information,” the researchers concluded.

“The use of legitimate websites such as JSON Keeper, JSON Silo and npoint.io, along with code repositories such as GitLab and GitHub, underlines the actor’s motivation and sustained attempts to operate stealthily and blend in with normal traffic.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article ChatGPT is testing group chats in the most chaotic way ChatGPT is testing group chats in the most chaotic way
Next Article An Exclusive Interview with Ryan Miersma, founder and president of EZE and How They are Helping Homeowners Keep Their Equity An Exclusive Interview with Ryan Miersma, founder and president of EZE and How They are Helping Homeowners Keep Their Equity
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

TikTok Influencer Marketing: 6 Insider Campaign Secrets Brands Ignore
TikTok Influencer Marketing: 6 Insider Campaign Secrets Brands Ignore
Computing
Parents voice screen time transparency concerns as school breaks approach
Parents voice screen time transparency concerns as school breaks approach
News
Grokipedia claims to aspire to the truth. An investigation has just shown that he cites neo-Nazi forums and conspiracy websites
Grokipedia claims to aspire to the truth. An investigation has just shown that he cites neo-Nazi forums and conspiracy websites
Mobile
Chinese Beverage Chains Spread Across the US, Challenging Starbucks’ Dominance
Chinese Beverage Chains Spread Across the US, Challenging Starbucks’ Dominance
Gadget

You Might also Like

TikTok Influencer Marketing: 6 Insider Campaign Secrets Brands Ignore
Computing

TikTok Influencer Marketing: 6 Insider Campaign Secrets Brands Ignore

6 Min Read
The HackerNoon Newsletter: The DeFAI Crucible: Navigating Trust and Automation in a Nascent Market (11/14/2025) | HackerNoon
Computing

The HackerNoon Newsletter: The DeFAI Crucible: Navigating Trust and Automation in a Nascent Market (11/14/2025) | HackerNoon

2 Min Read
AMD GCN 1.0/1.1 GPUs Will Default To AMDGPU Driver In Linux 6.19, SMART POWER OLED Added
Computing

AMD GCN 1.0/1.1 GPUs Will Default To AMDGPU Driver In Linux 6.19, SMART POWER OLED Added

3 Min Read
CATL seeks to manufacture batteries in the US pending Trump’s approval · TechNode
Computing

CATL seeks to manufacture batteries in the US pending Trump’s approval · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?