North Korean hackers create legitimate business fronts to trick crypto coders into downloading malware via fake job ads and interviews, exploiting an approach known as “deceptive recruitment tactics”. The operation, tied to a subgroup of the notorious Lazarus Group dubbed “Contagious Interview,” also employs AI-generated photos to fabricate employee profiles. Silent Push, the cybersecurity firm responsible for these findings, also tied three malware strains to the operation, all designed to pilfer crypto wallet information.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,