Skip to content

clean wagemole alias#1088

Merged
adulau merged 1 commit intoMISP:mainfrom
jashdalvi:clean-wagemole-alias
Jul 29, 2025
Merged

clean wagemole alias#1088
adulau merged 1 commit intoMISP:mainfrom
jashdalvi:clean-wagemole-alias

Conversation

@jashdalvi
Copy link
Contributor

per https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west, "contagious interview" is a campaign of wagemole and not an alias of it. This PR cleans the listed alias.

WageMole threat actors’ first step in applying for a job involves creating fake personas. WageMole threat actors obtain fake passports or other forms of identification, either through the Contagious Interview campaign or by purchasing them from real individuals. Occasionally, they hire foreign nationals residing in the U.S. In addition, WageMole threat actors create fake driver's licenses to verify their identity. In these cases, they appear to use stolen driver's licenses, altering only the photo on the ID while leaving the rest of the information unchanged.

@adulau
Copy link
Member

adulau commented Jul 29, 2025

Very good point. Thanks a lot for the contribution.

@adulau adulau merged commit bca6614 into MISP:main Jul 29, 2025
4 checks passed
@pkalnai
Copy link

pkalnai commented Sep 12, 2025

Hello, I'd like to ask why Contagious Interview was removed from the aliases for WageMole. There is an initial blog post by Palo Alto Networks from November 2023, where both codenames were introduced as two logically separated activity clusters (CI using the malware to steal from developers and WM to do proxy interviewing and job scams). Zscaler then claims that the first activity is just a subset of the latter. OK, that may be true, but all the malware like BeaverTail or InvisibleFerret is already linked to CI and now there is no such threat actor in the galaxy (e.g. this will be reflected in Malpedia https://malpedia.caad.fkie.fraunhofer.de/actor/wagemole) . Please reconsider removing the "Contagious Interview" from the WageMole, or create it as a new threat actor.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants