Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 3 2026-9-21 17:19:0 Author: thehackernews.com(查看原文) 阅读量:8 收藏

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.

The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. In all, the threat actors are estimated to have plundered at least $10.71 million worth of cryptocurrency from victims.

The alert comes courtesy of cybersecurity and intelligence agencies from Japan, the U.S., Australia, and Germany. The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.

The cyber threat group "conducts cyber attacks by infiltrating unsuspecting job seekers' computer networks, harvesting sensitive information, and stealing cryptocurrency," the alert said.

It's suspected that both WaterPlum and some North Korean IT workers (aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a June 2025 assessment from DTEX. What's more, the two clusters are said to be deeply intertwined, in some cases using the same IP addresses when accessing laptop farms and applying for positions at Japanese cryptocurrency exchanges.

Contagious Interview, first exposed by Palo Alto Networks Unit 42, is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the wild by posing as prospective employers and recruiters, and approaching them on social media platforms like LinkedIn under the pretext of lucrative job offers.

Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle.

The backdoor access afforded is then abused by the adversary to deliver remote access trojans for enabling persistent access and data exfiltration.

"Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients," the agencies said, adding a laptop farm operated by a facilitator in Japan has been identified and dismantled.

Furthermore, WaterPlum has been observed using online chat platforms to communicate with U.S. and Japanese developers, while employing enablers in Japan, the U.S., and other countries to set up and manage laptop farms for remote device management.

"Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments," the agencies noted. "Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency."

IT Worker Threat Expands to Discord for Recruiting Proxies

Complementing North Korea's offensive cyber capabilities is the infamous IT worker scheme, which is tasked with generating illicit revenue for the regime by landing jobs in Western companies and elsewhere under false identities. The operation is also known for increasingly relying on artificial intelligence (AI) to craft fictitious identities and expand its activities globally.

Sekoia, in its overview of North Korea's cyber operations, described the IT worker program as an adaptation of an established practice that involved the "dispatch of North Korean labor abroad to earn foreign currency dates to the 1960s and 1970s, beginning with logging in the Soviet Far East before broadening into construction, textiles and restaurant services across Russia, China, the Gulf and Africa."

According to a July 2026 analysis of the internal infrastructure linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.

In a report published last week, Silent Push said it identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named "Mouse Review," specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews so as to get around sanctions, geographic blocks, and compliance checks.

The AI-generated job advertisement claims: "YOUR ROLE IS SIMPLE, BUT CRUCIAL. You handle communications and interviews. I handle all technical work behind the scenes. You get paid consistently for your communication."

Facilitators who end up securing a job are eligible for anywhere between $3,000 and $5,000, the ad continues. "For live coding challenges, I can remotely access your screen and complete coding tasks while you continue the conversation smoothly."

"The North Korean IT worker's primary goal is proxy hiring, using Western or Latin American (LATAM) citizens as the 'face' and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions," Silent Push said. "The job ad scam offers a financial incentive split (35% to the proxy, 65% to the North Korean IT Worker) to incentivize foreign nationals to serve as financial and identity mules."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/09/contagious-interview-campaign.html
如有侵权请联系:admin#unsafe.sh