VYPR
breachPublished Sep 21, 2026· 1 source

North Korean 'Contagious Interview' Campaign Nets $10.7M, Compromises 30,000 Devices

A sophisticated North Korean cyber operation, dubbed 'Contagious Interview,' has compromised over 30,000 devices globally and stolen at least $10.71 million in cryptocurrency by impersonating recruiters and offering fake job opportunities.

North Korean threat actors are orchestrating a widespread cyber campaign known as 'Contagious Interview,' which has successfully compromised at least 30,000 devices across more than 100 countries. This operation, detailed in a joint advisory from cybersecurity agencies in Japan, the U.S., Australia, and Germany, has siphoned funds or credentials from over 7,000 cryptocurrency wallets, amassing at least $10.71 million in illicit gains.

The campaign's primary targets are individuals working in specialized fields such as web design, engineering, and cryptocurrency, blockchain, and Web3 technologies. The threat actors employ a deceptive tactic, posing as recruiters or potential employers on social media platforms like LinkedIn to lure victims with the promise of lucrative job offers. This long-running operation, first exposed by Palo Alto Networks Unit 42, has been active since at least 2022.

Once initial contact is made and a degree of trust is established, the attackers instruct their targets to complete a job assessment or coding test. This seemingly innocuous step initiates a multi-stage infection chain, leading to the deployment of various malware families. These include sophisticated tools such as BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle, granting the attackers backdoor access.

The compromised systems provide the adversaries with persistent access, enabling them to deploy remote access trojans for further data exfiltration and espionage. The advisory notes that some actors associated with this campaign, tracked under monikers like WaterPlum and PurpleDelta, may operate under North Korea's 313 General Bureau of the Munitions Industry Department, aligning with previous assessments. These groups are reportedly intertwined, sometimes sharing IP addresses when accessing laptop farms.

Further complicating the threat landscape, North Korean IT workers involved in this scheme are increasingly leveraging artificial intelligence (AI) to craft convincing fictitious identities and expand their global reach. The operation also relies on facilitators in various countries, including Japan and the U.S., to manage laptop farms used for remote device management. These facilitators help bypass sanctions, geographic restrictions, and compliance checks.

In a notable evolution of their tactics, threat actors have been observed using online chat platforms to communicate with potential victims and have even utilized Discord servers for recruitment proxies. Fake job advertisements, often crafted with AI assistance, promise simple roles involving communication and interviews, with the promise of significant financial incentives for individuals willing to act as intermediaries. These proxies are crucial for circumventing Know Your Customer (KYC) controls and regional hiring limitations.

The ultimate goal extends beyond immediate financial theft. Successful infiltration of organizations employing targeted developers allows for espionage, intellectual property theft, and lateral movement within corporate networks. Additionally, stolen identity images can be used by North Korean IT workers to impersonate victims and generate foreign currency, further fueling the regime's illicit revenue streams.

The broad international reach, sophisticated social engineering tactics, and significant financial impact underscore the evolving capabilities and persistent threat posed by North Korean state-sponsored cyber operations. The 'Contagious Interview' campaign highlights the critical need for enhanced vigilance among job seekers, particularly in the tech and cryptocurrency sectors, and for organizations to bolster their defenses against increasingly deceptive social engineering attacks.

Synthesized by Vypr AI
North Korean 'Contagious Interview' Campaign Nets $10.7M, Compromises 30,000 Devices · VYPR