North Korean Cyber Campaign Compromises 30,000 Devices Through Fake Job Interviews
A long-running North Korean cyber campaign known as Contagious Interview has compromised at least 30,000 devices across more than 100 countries, stealing cryptocurrency and sensitive credentials from thousands of victims.
According to a joint cybersecurity advisory issued by authorities from the United States, Japan, Australia and Germany, the campaign has targeted more than 7,000 cryptocurrency wallets and is believed to have stolen at least $10.71 million worth of cryptocurrency.
The attackers primarily target software developers, web designers, engineers and professionals working in cryptocurrency, blockchain and Web3 industries.
The campaign has been active since at least 2022. Rather than relying on traditional phishing emails, the attackers often approach potential victims through professional networking platforms such as LinkedIn.
The attackers pose as recruiters or prospective employers and offer attractive job opportunities. After establishing contact, they ask the target to complete a coding challenge, technical assessment or other recruitment task.
The seemingly legitimate test becomes the starting point for a malware infection.
Researchers have linked the campaign to numerous malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy and StoatWaffle.
After the initial infection, attackers can establish persistent remote access, steal credentials and extract sensitive information from the victim’s device.
The campaign is tracked by different security organizations under multiple names, including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi and WaterPlum.
Investigators have also identified connections between the cyber campaign and North Korea’s broader IT-worker operation. Some North Korean IT workers reportedly operate under false identities and obtain legitimate employment with foreign companies, creating another potential route into corporate networks.
Authorities have identified laptop farms used to remotely operate computers associated with these activities. Some of these operations reportedly involve facilitators in countries such as Japan and the United States.
The threat therefore extends beyond cryptocurrency theft.
If a developer working for a company becomes infected, attackers may gain an opportunity to access the employer’s systems. This can potentially lead to corporate espionage, intellectual-property theft, credential theft and lateral movement across internal networks.
Investigators have also found evidence that North Korean operators are using online communication platforms to recruit people in Western countries and Latin America to act as proxies during job interviews.
In one reported scheme, foreign individuals were offered thousands of dollars to participate in interviews while a North Korean IT worker remotely handled technical tasks. The arrangement could help North Korean operators bypass sanctions, identity verification procedures and geographic hiring restrictions.
The campaign demonstrates how fake recruitment has evolved into a sophisticated cyberattack technique. Organizations hiring technical workers therefore face risks not only from malicious applicants but also from apparently legitimate candidates who may use compromised systems or false identities to gain access to corporate environments.
Leave a comment