#hunting-lazarus

Introducing The Fake Interview: A Podcast on the Lazarus Hunt

A new Red Asgard podcast, The Fake Interview, brings the Contagious Interview investigation into audio: the operators, the personas, the infrastructure, the victims, and the operational mistakes that exposed more than the attackers intended.

Red Asgard
April 29, 2026
podcastlazarusdprkcontagious-interviewannouncement

A new Red Asgard podcast, The Fake Interview, brings the Contagious Interview investigation into audio: the operators, the personas, the infrastructure, the victims, and the operational mistakes that exposed more than the attackers intended.


DPRK-linked operators are running a Contagious Interview campaign against Web3 developers, smart contract engineers, and financial-sector workers. We've been tracking it across infrastructure, personas, and victim machines for months. The written series is at Hunting Lazarus.

The Fake Interview is the audio companion. Same investigation. Same evidence trail. Different format.

The written series documents a DPRK-linked, Lazarus-attributed Contagious Interview campaign: fabricated companies, persona operators, malicious code repositories, exfiltration pipelines, exposed infrastructure, and the developers, Web3 engineers, and financial-sector workers caught in the middle.

The podcast walks through the same material in a format that is easier to follow during a commute, a lab session, or while reviewing your own incident timeline.

Where to listen

The show is available on:

The Castopod hub is the canonical home for the show and includes the RSS feed for any podcast app.

Episode 1 companion technical notes are available here:

Companion Technical Notes: Episode 1 – Real Blood on the Wire

A consolidated landing page with embeds and direct subscribe links lives at:

redasgard.com/podcast

What the show is for

Three audiences, specifically:

Defenders and IR teams who keep seeing "fake recruiter" indicators in employee reports and want to understand what these campaigns look like end to end.

Threat researchers tracking the same infrastructure from a different angle: different telemetry, different access path, different conclusion. We compare notes.

Developers, freelancers, and Web3 contractors who are themselves the target. The fake interview is not only a story about companies being attacked. It is a story about developer laptops being attacked through job offers.

Each episode traces a specific finding: a forensic acquisition, a self-infection, a persona pipeline, a command chain, a cash-out workflow, or an infrastructure mistake. We do not narrate the research breathlessly. We walk through what happened, what the evidence supports, what remains unresolved, and what we deliberately leave out of the audio.

Cadence

New episodes will drop alongside the continuing research.

If you have followed the written series so far, the podcast follows the same evidence trail but adapts the order for audio. It starts where the stakes become undeniable, then walks through how the investigation got there: the fake interviews, malicious repositories, exposed infrastructure, victims, operators, and unanswered questions.

Subscribe wherever you listen. The show hub at podcast.redasgard.com carries the canonical feed for RSS-compatible apps including Overcast, Pocket Casts, AntennaPod, and others.

The investigation continues. Now it has a microphone too.

Share this article

Help spread the word about security best practices.

Need Security Help?

Our team can help secure your blockchain, web applications, and infrastructure.