Threat Summary
A live OTX pulse authored by AlienVault (TLP:WHITE, modified 2026-10-03), sourced from Jamf Threat Labs research, documents a significant tactical evolution in the Contagious Interview campaign — a long-running Democratic People's Republic of Korea (DPRK) state-sponsored operation historically associated with the Lazarus Group umbrella and its AppleJeus/Operation Dream Job lineage.
Contagious Interview has traditionally targeted software developers through fake job recruitment lures, tricking candidates into executing malicious "coding assessment" projects (typically weaponized npm/Python packages or trojanized IDE tooling). This pulse confirms the operation is stepping outside the developer workflow: Jamf identified a cluster of 14 trojanized macOS applications distributed as DMG and PKG installers impersonating widely used, legitimate consumer and productivity software — The Unarchiver, Sketch, and Bartender.
This pivot matters strategically. By moving from developer-specific lures to broadly popular macOS utilities, DPRK operators widen their victim funnel to any macOS user — designers, finance staff, executives, creatives — while retaining the fake-job-interview social engineering pretext as a delivery wrapper. DPRK cyber operations are financially motivated at the state level: objectives include cryptocurrency theft, credential harvesting, intellectual property exfiltration, and revenue generation to fund weapons programs. The initial payload family observed in this cluster is OtterCookie, a cross-platform JavaScript-based stealer/loader previously documented in Contagious Interview intrusions.
Threat Actor / Malware Profile
Adversary: DPRK (Contagious Interview cluster)
- Attribution: Democratic People's Republic of Korea state-nexus; overlaps with Lazarus Group / Diamond Sleet / UNC5342 reporting across vendor ecosystems.
- Social engineering: Fictitious recruiter personas on LinkedIn and freelance platforms; fake interview processes culminating in a "required software install" or "skills test" download.
- Objective set: Credential and session theft, browser crypto-wallet draining, keychain access, downstream loader capability for second-stage payloads.
Malware: OtterCookie (macOS trojanized installer chain)
- Distribution method: Trojanized DMG and PKG installers for The Unarchiver, Sketch, and Bartender, hosted on attacker-controlled infrastructure including
pobelstudio.com. Installers are unsigned or modified, stripping Gatekeeper's primary signature check. - Payload behavior: The trojanized app preserves legitimate application functionality to avoid suspicion while executing a hidden bundled executable. The chain retrieves and runs OtterCookie — a Node.js/JavaScript-family implant that beacons to C2, fingerprints the host, and stages credential/session theft modules.
- C2 communication: Outbound HTTPS to attacker-registered domains (e.g.,
pobelstudio.com) blending with normal web traffic; the malware commonly uses cloud-hosted C2 fronts to evade domain reputation filtering. - Persistence mechanism: Prior OtterCookie/Contagious Interview macOS variants establish persistence via LaunchAgents/LaunchDaemons plist entries (
~/Library/LaunchAgents/) and login items, often with innocuous or spoofed Apple-style labels. - Anti-analysis techniques: Unsigned/modified binaries to appear as cracked software (explaining away Gatekeeper warnings), hidden executables nested inside
.appbundles, delayed or conditional execution, and environment checks before detonating the second stage.
IOC Analysis
The pulse contains 38 indicators, dominated by two types:
- FileHash-SHA256 (37 samples): Hashes of the trojanized DMG/PKG installers and embedded payloads, including
01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b,08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9,0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39,0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab,0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29,1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91, and24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf. - Domain (1):
pobelstudio.com— distribution/C2 infrastructure.
Operationalization guidance for SOC teams:
- Hash blocking — Push all 37 SHA256 values into EDR custom blocklists (CrowdStrike, SentinelOne, Defender for Endpoint custom indicators), email/web gateway blocklists, and Jamf Pro restricted software definitions for macOS fleets.
- Domain interdiction — Sinkhole/block
pobelstudio.comat DNS (protective DNS, Pi-hole enterprise, Zscaler/Proxy) and alert on any historical resolution in passive DNS and proxy logs over the trailing 90 days. - Retrohunting — Sweep VMDR/EDR file telemetry for the hashes across all endpoints; DMG/PKG artifacts typically persist in
~/Downloadseven after installation. - Tooling — Use
shasum -a 256,codesign -dv --verbose=4,spctl -a -vv, andpkgutil --check-signatureto validate installer provenance; tools like Objective-See's KnockKnock and BlockBlock surface persistence items; VirusTotal/OTX pivoting expands the cluster.
Detection Engineering
---
title: OtterCookie / Contagious Interview Trojanized macOS Installer Execution
id: 7a3f1c2e-9b44-4d1a-8f6e-2c5d8e91a001
description: Detects execution of hidden or unsigned executables nested inside .app bundles and quarantined DMG/PKG installer artifacts associated with the DPRK Contagious Interview campaign (OtterCookie).
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: macos
service: null
detection:
selection_img:
Image|contains:
- '/Contents/MacOS/'
- '/Contents/Resources/'
- '/Volumes/'
selection_cli:
CommandLine|contains:
- 'The Unarchiver'
- 'Sketch'
- 'Bartender'
- '.app/Contents/MacOS/'
filter_signed:
Signed: 'true'
condition: selection_img and selection_cli and not filter_signed
falsepositives:
- Legitimate cracked/self-signed software installations (investigate provenance)
level: high
tags:
- attack.execution
- attack.t1059
- attack.t1204.002
date: 2026/10/04
modified: 2026/10/04
---
title: OtterCookie C2 or Staging Communication to Contagious Interview Infrastructure
id: 7a3f1c2e-9b44-4d1a-8f6e-2c5d8e91a002
description: Detects network connections to known Contagious Interview distribution/C2 domain (pobelstudio.com) including requests from scripting runtimes consistent with OtterCookie's JavaScript-based beaconing.
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: network_connection
product: macos
detection:
selection_domain:
DestinationHostname|contains:
- 'pobelstudio.com'
selection_initiated:
Initiated: 'true'
condition: all of selection_*
falsepositives:
- Threat research sandboxes (scope exclusions to lab VLANs)
level: critical
tags:
- attack.command_and_control
- attack.t1071.001
date: 2026/10/04
modified: 2026/10/04
---
title: Suspicious LaunchAgent/LaunchDaemon Persistence Creation on macOS
id: 7a3f1c2e-9b44-4d1a-8f6e-2c5d8e91a003
description: Detects creation or modification of LaunchAgents/LaunchDaemons plist files by non-Apple processes, consistent with OtterCookie/Contagious Interview persistence behavior.
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: file_event
product: macos
detection:
selection_path:
TargetFilename|contains:
- '/Library/LaunchAgents/'
- '/Library/LaunchDaemons/'
- 'Library/LaunchAgents/'
TargetFilename|endswith: '.plist'
filter_apple:
Image|contains:
- '/usr/libexec/'
- '/System/Library/'
Image|startswith: 'com.apple.'
condition: selection_path and not filter_apple
falsepositives:
- Enterprise MDM enrollment, legitimate third-party updaters (Google Keystone, Microsoft AutoUpdate)
level: medium
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1543.001
- attack.t1543.004
date: 2026/10/04
modified: 2026/10/04
// Contagious Interview / OtterCookie hunt — Microsoft Sentinel
// 1) Network connections to known C2/distribution domain
let C2Domains = dynamic(["pobelstudio.com"]);
let NetHits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl has_any (C2Domains) or RemoteUrl contains "pobelstudio"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType;
// 2) Trojanized installer execution from Downloads/mounted DMGs
let ProcHits = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where ProcessCommandLine has_any ("The Unarchiver", "Bartender", "Sketch")
and (ProcessCommandLine has_any ("/Volumes/", "~/Downloads", "/tmp/", ".app/Contents/MacOS/"))
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256;
// 3) Known-bad SHA256 sweep
let BadHashes = dynamic([
"01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b",
"08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9",
"0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39",
"0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab",
"0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29",
"1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91",
"24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf"
]);
let HashHits = DeviceFileEvents
| where TimeGenerated > ago(30d)
| where SHA256 has_any (BadHashes)
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, ActionType;
union NetHits, ProcHits, HashHits
| sort by TimeGenerated desc
#!/bin/bash
# Contagious Interview / OtterCookie macOS IOC Hunt — run via MDM (Jamf/Intune) or locally with sudo
# Checks for trojanized installer hashes, C2 connections, and suspicious persistence artifacts.
BAD_HASHES=(
"01955691147a036e2104a16f9c3b34d11cb3304e184ed9d533325705599b876b"
"08425172a2dc19516ba9a3fcca8a0a789962d9b95d1792974f69c086ee64aec9"
"0882bb158878a1ca19320f5160dc93f4608c862f3ab652671bb92a82b2f1eb39"
"0d306f347999e02cbbe41d6ff1c47aecbc994213b3cc65bbf4aa723469e6e5ab"
"0e12f41c2d3d2e48b5a004bff4c126bf8e907bc6c20648f3844ed4ebad126a29"
"1abbdeee6d03894c0c53240f7ba873fadf9367e312ada1d280420bc88f986e91"
"24a252e72d767d62f3076f4f59780511288ea9eedd0e30f234c9cdd5b7644cbf"
)
C2_DOMAIN="pobelstudio.com"
REPORT="/tmp/contagious_interview_hunt_$(date +%Y%m%d_%H%M%S).txt"
echo "=== Contagious Interview / OtterCookie Hunt — $(hostname) — $(date) ===" | tee "$REPORT"
echo -e "\n[1] Hash sweep of Downloads, /tmp, /Applications for known-bad SHA256..." | tee -a "$REPORT"
find ~/Downloads /tmp /Applications -type f \( -name "*.dmg" -o -name "*.pkg" -o -name "*.app" -o -type f \) 2>/dev/null | while read -r f; do
h=$(shasum -a 256 "$f" 2>/dev/null | awk '{print $1}')
for bad in "${BAD_HASHES[@]}"; do
if [[ "$h" == "$bad" ]]; then
echo "[ALERT] MALICIOUS HASH: $f ($h)" | tee -a "$REPORT"
fi
done
done
echo -e "\n[2] Checking active/recent connections to C2 domain..." | tee -a "$REPORT"
lsof -i 2>/dev/null | grep -i "$C2_DOMAIN" | tee -a "$REPORT"
log show --last 24h --predicate 'eventMessage CONTAINS "pobelstudio"' 2>/dev/null | head -20 | tee -a "$REPORT"
echo -e "\n[3] Auditing LaunchAgents/LaunchDaemons for non-Apple persistence..." | tee -a "$REPORT"
for dir in ~/Library/LaunchAgents /Library/LaunchAgents /Library/LaunchDaemons; do
if [[ -d "$dir" ]]; then
for plist in "$dir"/*.plist; do
[[ -e "$plist" ]] || continue
label=$(/usr/libexec/PlistBuddy -c "Print :Label" "$plist" 2>/dev/null)
if [[ "$label" != com.apple.* ]]; then
echo "[REVIEW] $plist (Label: $label)" | tee -a "$REPORT"
/usr/libexec/PlistBuddy -c "Print :ProgramArguments" "$plist" 2>/dev/null | tee -a "$REPORT"
fi
done
fi
done
echo -e "\n[4] Checking for unsigned/modified installs of impersonated apps..." | tee -a "$REPORT"
for app in "/Applications/The Unarchiver.app" "/Applications/Sketch.app" "/Applications/Bartender 5.app" "/Applications/Bartender 4.app"; do
if [[ -d "$app" ]]; then
sig=$(codesign -dv "$app" 2>&1 | grep -E "Authority|Signature" | head -2)
spctl_out=$(spctl -a -vv "$app" 2>&1)
echo "[APP] $app" | tee -a "$REPORT"
echo " $sig" | tee -a "$REPORT"
echo " Gatekeeper: $spctl_out" | tee -a "$REPORT"
fi
done
echo -e "\n=== Hunt complete. Results: $REPORT ==="
Response Priorities
Immediate (0–4 hours)
- Block
pobelstudio.comat DNS resolver, web proxy, and EDR network controls; sinkhole where possible to identify infected hosts. - Push all 37 SHA256 hashes into EDR blocklists and Jamf Pro restricted software; retrohunt the trailing 90 days of file telemetry.
- Sweep for quarantined DMG/PKG artifacts in user
~/Downloadsmatching The Unarchiver, Sketch, or Bartender from non-official sources.
24 Hours
- OtterCookie is a credential/session stealer: for any host with confirmed execution or C2 contact, force enterprise-wide credential resets for that user — IdP sessions, SSO tokens, browser-stored passwords, SSH keys, and macOS keychain entries. Assume browser cookies and crypto-wallet data are compromised.
- Revoke active sessions and refresh tokens; audit for anomalous OAuth grants and new MFA device enrollments.
- Interview affected users for recruiter/social engineering contact (LinkedIn, Telegram, freelance platforms) to identify the lure persona and report accounts.
1 Week
- Enforce Gatekeeper/XProtect hardening: block unsigned application execution via MDM configuration profiles; require notarized apps only where feasible.
- Deploy software provenance policy — mandate installs via managed self-service (Jamf App Catalog/company portal) and block sideloaded DMG/PKG from Downloads.
- Add the Sigma rules and KQL analytics above to production SIEM; enable macOS Unified Log collection for
pobelstudio.comstring matches. - Run targeted awareness for engineering, design, and finance staff on fake-job-interview lures — DPRK recruiter personas are persistent and professionally maintained.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.