North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

North Korean hackers are using JSON storage services like JSON Keeper and JSONsilo as covert malware delivery channels within the Contagious Interview campaign. These threat actors leverage social engineering on professional networking sites to trick developers into downloading trojanized projects, which then fetch JavaScript malware like BeaverTail and Python backdoors.

Edward Kiledjian @ekiledjian