The Fake Interview

Eleven Hours: Inside the Lazarus Operator’s Disk After the Fake Interview Campaign

25 min · 20. maj 2026
episode Eleven Hours: Inside the Lazarus Operator’s Disk After the Fake Interview Campaign cover

Description

A live adversary server. Two password changes. Eleven hours. Episode 04 follows the forensic window where researchers preserved a contested Windows machine used in a Lazarus-attributed fake-interview campaign, uncovering the operator workbench behind the lures: campaign archives, fake-company material, targeting pipelines, wallet artifacts, browser traces, and signs of AI-assisted workflow.

Comments

0

Be the first to comment

Sign up now and become a member of the The Fake Interview community!

Get Started

2 months for 19 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

6 episodes

episode The Repository That Called Home: Lazarus, Fake Interviews, and Malicious Code artwork

The Repository That Called Home: Lazarus, Fake Interviews, and Malicious Code

Episode 2 of The Fake Interview follows the first repository: a fake software project delivered through a job interview that behaved like real work until the moment it called home. We examine how a malicious coding test abused normal developer behavior: opening a project, trusting a workspace, installing dependencies, running local code, and debugging what looked like a broken app. This episode covers: - DPRK-linked fake interview activity - malicious GitHub / contractor repositories - VSCode and Cursor workspace trust abuse - run-on-folder-open execution - Function.constructor abuse in JavaScript - Vercel-hosted stage-one infrastructure - payload delivery and command-and-control routing - why developer machines are high-value targets Companion notes: https://podcast.redasgard.com/pages/companion-technical-notes-episode-02-the-repository-that-called-home

6. maj 202624 min