The Fake Interview
A narrative threat-hunting podcast from Red Asgard.
A fake coding interview.
A malicious repository.
A credential-theft operation targeting developers, Web3 engineers, and financial infrastructure.
The Fake Interview follows a real investigation into a DPRK-linked, Lazarus-attributed campaign that used fake recruiter personas, malicious coding tests, exposed command-and-control infrastructure, malware payloads, blockchain dead drops, and operator mistakes.
Start with Episode 1
Episode 1: Real Blood on the Wire
At first, the infrastructure looked too perfect. It might have been a honeypot. Then the investigation found real victims, real credentials, and real operational consequences.
Listen on:
Who this is for
This series is for:
- security researchers
- threat intelligence teams
- software developers
- Web3 engineers
- red teams
- incident responders
- anyone asked to clone and run code during an interview
Developer warning
Do not run unknown coding-test repositories on your main machine.
Before opening any interview project:
- verify the company and recruiter independently
- avoid running code during a live interview
- inspect
.vscode/,package.json, install scripts, and postinstall hooks - use a disposable VM or isolated machine
- assume browser sessions, wallet files, SSH keys, and source tokens are targets
About Red Asgard
Red Asgard Security Research investigates real-world offensive infrastructure, malware campaigns, Web3 compromise, and developer-targeted attacks.
Website: https://redasgard.com