Cinema & Photography, A/V Tech, Musician, Convention Organizer.
Certified Horse.
I break things and I make things.
Definitely not a giant space octopus.
@AzakaSekai_@1ZRR4H I believe it is ContagiousInterview. The first part is similar to the OtterCookie first stage described here: https://t.co/LqhVxnBmOk, payload is a newer version of BeaverTail.
@psifertex@github If you manage to fight your way through the recursive support and help pages and defeat an AI support agent clearly meant only to gatekeep you, you can open an actual support ticket that will be reviewed by their security team and in it list as many abuse instances as you want...
@L0Psec@malwrhunterteam That matches one of the stealers used by DeceptiveDevelopment/ContagiousInterview. Likely NK-affiliated, but the context around it is definitely something new.
@malwrhunterteam@patrickwardle This looks like another version of the fake password prompt used to steal user passwords in this DPRK-aligned campaign related to DeceptiveDevelopment/ContagiousInterview (here named ChromeUpdateAlert): https://t.co/SjtEdXcdq1
It even uses the same Dropbox API key.
@malwrhunterteam I know I am but one of many who value your insights and ability to spot interesting samples. I thought you were just taking a break, we all need those. Nobody can be expected to tweet about malware non-stop.
@souldestrings@wuchta7 It looks like a bunch of samples of early Czech electronic music. You can find the origins for some of them by googling, others are a mystery even for me.