Ethical Hacking News
A malicious campaign known as the "Contagious Interview" has compromised at least 30,000 devices, stealing $10.71 million in cryptocurrency, and is believed to be the work of North Korean threat actors. The campaign is part of a larger global threat landscape that includes other malicious activities, such as the infamous IT worker scheme, which is tasked with generating illicit revenue for the North Korean regime.
At least 30,000 devices in over 100 countries have been compromised by the "Contagious Interview" campaign, resulting in a $10.71 million loss in cryptocurrency. The campaign is believed to be the work of North Korean threat actors, using tactics such as phishing, malware, and social engineering. The primary targets are individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The campaign has been ongoing since at least 2022, targeting software developers and IT professionals across the globe. The threat actors use AI-generated job advertisements and social media platforms to recruit victims. The campaign has been linked to other North Korean cyber operations, including the IT worker scheme. The IT worker scheme uses proxy hiring to bypass sanctions, KYC controls, and regional hiring restrictions.
The cybersecurity community has been alerted to a concerning global threat landscape, with a malicious campaign known as the "Contagious Interview" compromising at least 30,000 devices located in over 100 countries. According to a joint cybersecurity advisory, the threat actors behind this campaign have siphoned funds or account credentials from over 7,000 cryptocurrency wallets, resulting in a staggering loss of at least $10.71 million worth of cryptocurrency.
The Contagious Interview campaign is believed to be the work of North Korean threat actors, who have been using various tactics to infiltrate unsuspecting job seekers' computer networks, harvest sensitive information, and steal cryptocurrency. The campaign is tracked by several monikers, including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
The campaign's primary targets are individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The threat actors are suspected to be operating under the 313 General Bureau of the Munitions Industry Department, corroborating a June 2025 assessment from DTEX. Furthermore, it is believed that both WaterPlum and some North Korean IT workers (known as PurpleDelta or Wagemole) are involved in the operation.
The Contagious Interview campaign is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the globe by posing as prospective employers and recruiters on social media platforms like LinkedIn. Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle.
The backdoor access afforded by the malware allows the adversary to deliver remote access trojans for enabling persistent access and data exfiltration. The threat actors have also been observed using online chat platforms to communicate with U.S. and Japanese developers, while employing enablers in Japan, the U.S., and other countries to set up and manage laptop farms for remote device management.
In addition to the Contagious Interview campaign, the global cybersecurity landscape has seen a rise in other malicious activities, including the infamous IT worker scheme, which is tasked with generating illicit revenue for the North Korean regime by landing jobs in Western companies and elsewhere under false identities. This operation is also known for increasingly relying on artificial intelligence (AI) to craft fictitious identities and expand its activities globally.
Sekoia's overview of North Korea's cyber operations describes the IT worker program as an adaptation of an established practice that involved the "dispatch of North Korean labor abroad to earn foreign currency" dating back to the 1960s and 1970s. According to a July 2026 analysis of the internal infrastructure linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.
In a report published last week, Silent Push identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named "Mouse Review," specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews. The AI-generated job advertisement claims that the role is simple but crucial, with the threat actor handling technical work behind the scenes and the proxy handling communications and interviews.
Facilitators who end up securing a job are eligible for anywhere between $3,000 and $5,000, the ad continues. "For live coding challenges, I can remotely access your screen and complete coding tasks while you continue the conversation smoothly." The North Korean IT worker's primary goal is proxy hiring, using Western or Latin American citizens as the "face" and legal identity to bypass sanctions, KYC controls, and regional hiring restrictions.
The Contagious Interview campaign and the IT worker scheme highlight the evolving nature of global cyber threats, with threat actors increasingly relying on social engineering, AI, and other tactics to compromise sensitive information and steal cryptocurrency. As the global cybersecurity landscape continues to evolve, it is essential for organizations and individuals to remain vigilant and take proactive measures to protect themselves against these emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Global-Cyber-Threat-Landscape-Contagious-Interview-Campaign-Exposes-30000-Devices-Steals-1071M-in-Crypto-ehn.shtml
https://thehackernews.com/2026/09/contagious-interview-campaign.html
Published: Mon Sep 21 14:22:06 2026 by llama3.2 3B Q4_K_M