Back to Intelligence

Contagious Interview Expands to Trojanized macOS Installers: DPRK OtterCookie Campaign — OTX Pulse Analysis & Detection Pack

SA
Security Arsenal Team
October 3, 2026
9 min read

Classification: TLP:WHITE | Pulse Author: AlienVault | Attribution: DPRK (North Korea) | Malware Family: OtterCookie


Threat Summary

A new OTX pulse confirms that the DPRK-attributed Contagious Interview operation has evolved beyond its traditional developer-focused delivery model. Jamf Threat Labs identified a cluster of 14 trojanized macOS applications distributed as DMG and PKG installers, impersonating widely trusted utilities including The Unarchiver, Sketch, and Bartender. This represents a deliberate broadening of the campaign's victimology: instead of targeting only software engineers lured through fake job interviews with malicious coding assessments, the operators are now poisoning general-purpose macOS software distribution channels.

The campaign's objective remains consistent with DPRK financial-motivation operations: credential harvesting, cryptocurrency wallet theft, browser session theft, and initial access for downstream infostealer activity. The malware chain begins inside unsigned, modified application bundles that conceal embedded executables alongside the legitimate application logic — meaning the victim receives a fully functional app while OtterCookie stages in the background. The domain pobelstudio.com serves as identified malicious infrastructure, and 38 indicators including multiple SHA-256 hashes are available for immediate blocking.

For enterprise defenders, the critical takeaway is this: macOS endpoints in developer, design, and creative teams are now front-line targets of a state-sponsored credential theft campaign, and Gatekeeper alone will not stop unsigned-but-user-approved execution.

Threat Actor / Malware Profile

Contagious Interview (DPRK)

Contagious Interview is a North Korean state-sponsored operation historically attributed to clusters overlapping with Lazarus Group activity. Its hallmark social engineering is the fake job interview pretext — recruiters on LinkedIn, Upwork, and Telegram approach targets with lucrative roles, then deliver malware disguised as interview materials, coding tests, or video conferencing tools.

OtterCookie (macOS variant)

AttributeDetail
DistributionTrojanized DMG/PKG installers impersonating The Unarchiver, Sketch, Bartender, and 11 other legitimate apps; delivered via fake interview lures and poisoned download sites
Payload behaviorHidden embedded executables execute alongside the legitimate app; harvests browser cookies, saved credentials, keychain material, and cryptocurrency wallet data; exfiltrates staged archives
C2 communicationHTTPS-based beaconing to attacker infrastructure including pobelstudio.com; staging and exfil over standard web ports to blend with legitimate traffic
PersistenceLaunchAgents/LaunchDaemons plist installation in ~/Library/LaunchAgents and /Library/LaunchDaemons; masquerades under benign-sounding labels mimicking Apple or app-update services
Anti-analysisUnsigned or ad-hoc signed binaries to avoid notarization artifacts; payloads embedded within otherwise-functional application bundles; execution only after user-driven install (evades sandbox detonation)

The use of functional trojanized apps is a high-efficacy technique: users install, run, and trust the software because it works, suppressing suspicion while the implant persists and exfiltrates session material — a direct pipeline into enterprise SSO, cloud consoles, and developer credential stores (SSH keys, AWS/GCP/Azure CLI tokens).

IOC Analysis

The pulse contains 38 indicators across two types:

  • Domain indicators (1 shown): pobelstudio.com — malicious C2/distribution infrastructure. Operationalize via DNS sinkholing, egress proxy block, and retro-hunt across DNS query logs for the past 90 days.
  • FileHash-SHA256 indicators (6 shown, 37 total): Hashes of the trojanized DMG/PKG files and embedded payloads. Operationalize via EDR blocklists (CrowdStrike custom IOC, Defender for Endpoint indicators, SentinelOne blacklist) and retroactive hash sweeps across all macOS endpoints.

SOC operationalization guidance:

  1. Import the full 38-IOC set into your TIP (MISP, ThreatConnect, or direct OTX integration via the OTX DirectConnect API / OTXv2 Python SDK).
  2. Hash-based detection is fragile — DPRK operators repackage installers frequently. Pair hash blocking with behavioral detections (unsigned app spawning child processes, LaunchAgent creation from user-installed apps).
  3. Domain indicators decay; enrich pobelstudio.com with passive DNS to identify co-hosted infrastructure and pivot to related delivery domains.
  4. On macOS, use codesign -dv --verbose=4 and spctl -a -vv during triage to confirm signature/notarization status of any app matching the impersonated products.

Detection Engineering

The following detections target: (1) unsigned macOS app execution from user-mounted DMGs, (2) LaunchAgent persistence creation by recently-installed applications, and (3) network beacons to known OtterCookie C2 infrastructure.

YAML
---
title: Unsigned macOS Application Execution from Mounted DMG
id: 7c3f1a2e-9d41-4b8a-a6f2-ottercookie001
status: experimental
description: Detects execution of unsigned or ad-hoc signed binaries from DMG-mounted volumes or quarantined downloads, consistent with Contagious Interview trojanized installers (OtterCookie)
author: Security Arsenal Threat Intelligence
date: 2026/10/04
references:
    - https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
logsource:
    category: process_creation
    product: macos
detection:
    selection_path:
        Image|startswith:
            - '/Volumes/'
            - '/private/var/folders/'
    selection_tmp:
        Image|contains:
            - '/Library/Caches/'
            - 'AppTranslocation'
    condition: selection_path or selection_tmp
falsepositives:
    - Legitimate unsigned open-source tools run from disk images
level: medium
tags:
    - attack.execution
    - attack.t1204.002
---
title: LaunchAgent Persistence Created by User-Installed Application
id: 8d4a2b3f-1e52-5c9b-b7a3-ottercookie002
status: experimental
description: Detects creation of LaunchAgent/LaunchDaemon plist files by non-Apple processes, a persistence mechanism used by OtterCookie in the Contagious Interview campaign
author: Security Arsenal Threat Intelligence
date: 2026/10/04
references:
    - https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
logsource:
    category: file_event
    product: macos
detection:
    selection:
        TargetFilename|contains:
            - '/Library/LaunchAgents/'
            - '/Library/LaunchDaemons/'
        TargetFilename|endswith: '.plist'
    filter_apple:
        SourceImage|startswith:
            - '/System/'
            - '/usr/libexec/'
    condition: selection and not filter_apple
falsepositives:
    - Legitimate software updaters installing helper agents
level: high
tags:
    - attack.persistence
    - attack.t1543.001
    - attack.t1543.004
---
title: OtterCookie C2 Communication to Known Malicious Infrastructure
id: 9e5b3c4a-2f63-6d1c-c8b4-ottercookie003
status: experimental
description: Detects DNS resolution or network connection to pobelstudio.com, identified C2/distribution infrastructure for the DPRK Contagious Interview OtterCookie campaign
author: Security Arsenal Threat Intelligence
date: 2026/10/04
references:
    - https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
logsource:
    category: dns
detection:
    selection:
        query|contains: 'pobelstudio.com'
    condition: selection
falsepositives:
    - Threat research and sandbox detonation
level: critical
tags:
    - attack.command_and_control
    - attack.t1071.001
KQL — Microsoft Sentinel / Defender
// Hunt: OtterCookie / Contagious Interview activity — C2 beacons, trojanized installer hashes, and macOS persistence
let OtterCookieHashes = dynamic([
    "01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b",
    "08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9",
    "0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39",
    "0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab",
    "0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29",
    "1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91",
    "24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf"
]);
let C2Domain = "pobelstudio.com";
let NetHits = DeviceNetworkEvents
    | where TimeGenerated > ago(30d)
    | where RemoteUrl has C2Domain
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType;
let DnsHits = DeviceNetworkEvents
    | where TimeGenerated > ago(30d)
    | where RemoteUrl has C2Domain
    | summarize ConnectionCount=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by DeviceName, RemoteIP;
let HashHits = DeviceProcessEvents
    | where TimeGenerated > ago(30d)
    | where SHA256 in~ (OtterCookieHashes)
    | project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, ProcessCommandLine, AccountName;
let PersistenceHits = DeviceFileEvents
    | where TimeGenerated > ago(30d)
    | where FolderPath has_any ("LaunchAgents", "LaunchDaemons") and FileName endswith ".plist"
    | where InitiatingProcessFolderPath !startswith "/System/"
    | project TimeGenerated, DeviceName, FolderPath, FileName, InitiatingProcessFileName, SHA256;
union NetHits, HashHits, PersistenceHits
| sort by TimeGenerated desc
Bash / Shell
#!/bin/bash
# Security Arsenal — OtterCookie / Contagious Interview macOS IOC Hunt
# Run via MDM (Jamf/Intune) or manually with sudo on macOS endpoints

echo "=== OtterCookie IOC Hunt: $(hostname) — $(date) ==="

KNOWN_HASHES=(
"01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b"
"08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9"
"0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39"
"0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab"
"0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29"
"1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91"
"24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf"
)

echo "[1/5] Scanning /Applications and ~/Downloads for known malicious hashes..."
for dir in /Applications ~/Downloads /tmp; do
  [ -d "$dir" ] || continue
  find "$dir" -type f \( -name "*.dmg" -o -name "*.pkg" -o -perm +111 \) 2>/dev/null | while read -r f; do
    h=$(shasum -a 256 "$f" 2>/dev/null | awk '{print $1}')
    for kh in "${KNOWN_HASHES[@]}"; do
      [ "$h" == "$kh" ] && echo "  [ALERT] Malicious hash match: $f"
    done
  done
done

echo "[2/5] Checking for unsigned copies of impersonated applications..."
for app in "The Unarchiver" "Sketch" "Bartender"; do
  app_path=$(mdfind "kMDItemCFBundleIdentifier == '*'" 2>/dev/null | grep -i "$app.app" | head -1)
  if [ -n "$app_path" ]; then
    if ! codesign -v "$app_path" 2>/dev/null; then
      echo "  [ALERT] Unsigned/modified app: $app_path"
    fi
    spctl -a -vv "$app_path" 2>&1 | grep -qi "rejected" && echo "  [ALERT] Notarization rejected: $app_path"
  fi
done

echo "[3/5] Auditing LaunchAgents/LaunchDaemons for suspicious persistence..."
for plist_dir in /Library/LaunchAgents /Library/LaunchDaemons ~/Library/LaunchAgents; do
  [ -d "$plist_dir" ] || continue
  find "$plist_dir" -name "*.plist" -mtime -30 2>/dev/null | while read -r p; do
    label=$(/usr/libexec/PlistBuddy -c "Print :Label" "$p" 2>/dev/null)
    prog=$(/usr/libexec/PlistBuddy -c "Print :ProgramArguments:0" "$p" 2>/dev/null)
    case "$prog" in /System/*|/usr/libexec/*) continue;; esac
    echo "  [REVIEW] Recent persistence: $p | Label=$label | Exec=$prog"
  done
done

echo "[4/5] Checking DNS cache and active connections for pobelstudio.com..."
lsof -i -n -P 2>/dev/null | grep -i "pobelstudio" && echo "  [ALERT] Active C2 connection detected"
log show --predicate 'process == "mDNSResponder"' --last 24h --style compact 2>/dev/null | grep -i "pobelstudio.com" && echo "  [ALERT] C2 domain in DNS query log"

echo "[5/5] Checking for App Translocation artifacts and hidden executables in app bundles..."
ls -d /private/var/folders/*/*/*/AppTranslocation/* 2>/dev/null | head -20
find /Applications -type f -perm +111 -not -path "*/Contents/MacOS/*" 2>/dev/null | head -20 | while read -r h; do
  echo "  [REVIEW] Hidden executable in bundle: $h"
done

echo "=== Hunt complete. Escalate any [ALERT] findings to IR immediately. ==="

Response Priorities

Immediate (0–4 hours)

  • Block pobelstudio.com at DNS resolver, egress proxy, and firewall layers; import all 38 pulse indicators into EDR hash blocklists.
  • Sweep all macOS endpoints for the published SHA-256 hashes and any DNS resolution of the C2 domain over the trailing 90 days.
  • Audit /Applications for copies of The Unarchiver, Sketch, and Bartender installed outside the Mac App Store or official vendor channels; verify code signatures and notarization status.

24 Hours

  • Treat any confirmed OtterCookie execution as a full credential compromise. Force revocation and rotation of: browser-saved credentials, macOS Keychain entries, SSO session tokens, SSH private keys, cloud CLI tokens (AWS/GCP/Azure), and cryptocurrency wallet access for the affected user.
  • Invalidate all active sessions for affected identities in Entra ID/Okta; require re-authentication with phishing-resistant MFA.
  • Interview affected users to identify the delivery vector (recruiter contact, download link, interview task) — this feeds attribution and blocks repeat targeting of teammates.

1 Week

  • Enforce Gatekeeper + notarization policy via MDM: block execution of unsigned applications org-wide (spctl --master-enable equivalents via configuration profile).
  • Deploy application allowlisting (Santa, Jamf Protect, or MDE custom indicators) restricting execution to notarized, hash- or team-ID-approved software.
  • Alert on LaunchAgent/LaunchDaemon creation by non-system processes as a standing detection, and brief engineering/design teams on Contagious Interview social engineering lures — fake recruiter outreach remains the primary infection vector.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.