North Korean hackers target Microsoft Virtual Studio Code


  • The Lazarus group’s Contagious Interview campaign exploits Visual Studio Code via malicious Git repositories
  • Attackers deliver JavaScript payloads on macOS that enable persistent data collection and C2 communication
  • Jamf urges you to enable advanced threat controls and caution against untrusted repositories

As part of the infamous Contagious Interview campaign, North Korean threat actors were seen misusing legitimate Microsoft Visual Studio Code in their attacks.

Contagious Interview is a hacking campaign in which the Lazarus group (and other state-sponsored North Korean actors) create fake jobs and invite software and blockchain developers in Western countries for interviews.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top