The Fake Interview

the FTP Server: How One Boring Label Hid a Second Layer of the Campaign

34 min · 28. maj 2026
episode the FTP Server: How One Boring Label Hid a Second Layer of the Campaign cover

Beskrivelse

Episode 05 focuses on how infrastructure can be misclassified during an active investigation. The server discussed here was initially understood through its FTP exfiltration role. Later evidence tied the same host to additional campaign-linked services, including OtterCookie-related collection behavior.

Kommentarer

0

Vær den første til at kommentere

Tilmeld dig nu og bliv en del af The Fake Interview-fællesskabet!

Kom i gang

1 måned kun 9 kr.

Derefter 99 kr. / måned · Opsig når som helst.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

Alle episoder

7 episoder

episode OtterCookie – The Malware That Watched the Developer cover

OtterCookie – The Malware That Watched the Developer

Every five seconds, OtterCookie took another look at the workstation. Episode 06 of The Fake Interview examines OtterCookie, a second-stage malware family associated with DPRK-linked Contagious Interview activity. Where earlier stages helped explain how fake technical interviews moved developers from conversation to code execution, OtterCookie shows what the operation wanted after the code was already running. This episode focuses on the real target: the developer workstation. Not an empty sandbox. Not a clean analysis VM. The real machine, with browser history, terminal residue, clipboard activity, authenticated sessions, wallets, cloud consoles, source-control access, and work still in motion. OtterCookie matters because it moved the compromise from static theft toward live observation. A credential dump captures one moment. A watcher can wait for the work to happen. In this episode: OtterCookie’s role in the broader fake-interview pipeline Why screenshots and keyboard capture mean something different on real workstations Why clean sandboxes can miss the operational value of the implant How wallet targeting changes the personal stakes for Web3 developers Why “use a VM” is right, but incomplete Why the developer became the perimeter This episode avoids live indicators, exploit walkthroughs, victim records, and reusable operational detail. The goal is to explain the campaign safely: what changed, why it mattered, and what developers and defenders should understand. The real workstation was the target. The Fake Interview is a narrative technical podcast from Red Asgard about DPRK-linked fake interview campaigns targeting developers.

6. juni 202628 min