The Fake Interview

the FTP Server: How One Boring Label Hid a Second Layer of the Campaign

34 min · 28 de may de 2026
Portada del episodio the FTP Server: How One Boring Label Hid a Second Layer of the Campaign

Descripción

Episode 05 focuses on how infrastructure can be misclassified during an active investigation. The server discussed here was initially understood through its FTP exfiltration role. Later evidence tied the same host to additional campaign-linked services, including OtterCookie-related collection behavior.

Comentarios

0

Sé la primera persona en comentar

¡Regístrate ahora y únete a la comunidad de The Fake Interview!

Prueba gratis

Empieza 7 días de prueba

$99 / mes después de la prueba. · Cancela cuando quieras.

  • Podcasts solo en Podimo
  • 20 horas de audiolibros al mes
  • Podcast gratuitos

Todos los episodios

6 episodios

episode The Repository That Called Home: Lazarus, Fake Interviews, and Malicious Code artwork

The Repository That Called Home: Lazarus, Fake Interviews, and Malicious Code

Episode 2 of The Fake Interview follows the first repository: a fake software project delivered through a job interview that behaved like real work until the moment it called home. We examine how a malicious coding test abused normal developer behavior: opening a project, trusting a workspace, installing dependencies, running local code, and debugging what looked like a broken app. This episode covers: - DPRK-linked fake interview activity - malicious GitHub / contractor repositories - VSCode and Cursor workspace trust abuse - run-on-folder-open execution - Function.constructor abuse in JavaScript - Vercel-hosted stage-one infrastructure - payload delivery and command-and-control routing - why developer machines are high-value targets Companion notes: https://podcast.redasgard.com/pages/companion-technical-notes-episode-02-the-repository-that-called-home

6 de may de 202624 min