North Korean Contagious Interview Campaign Compromises 30,000 Devices Across 100 Countries
North Korean threat actors behind the long-running Contagious Interview campaign have compromised at least 30,000 devices across more than 100 countries and stolen funds or account credentials from more than 7,000 cryptocurrency wallets, according to a joint cybersecurity advisory published by government agencies from Japan, the United States, Australia, and Germany.
The campaign primarily targets web designers, software engineers, and professionals working in cryptocurrency, blockchain, and Web3 technologies. Investigators estimate that the attackers have stolen at least $10.71 million worth of cryptocurrency from victims.
The activity is tracked by the cybersecurity community under multiple names, including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.
According to the advisory, the threat actors compromise the computers of unsuspecting job seekers, steal sensitive information, and target cryptocurrency assets.
Campaign Uses Fake Job Opportunities
The Contagious Interview campaign has been active since at least 2022 and targets software developers and IT professionals by posing as recruiters or prospective employers.
Threat actors typically approach victims through platforms such as LinkedIn and offer attractive job opportunities.
After establishing contact, attackers instruct the target to complete a coding assessment, technical interview, or job-related task.
The assessment is used as the entry point for a multi-stage malware infection.
Successful infections can result in the deployment of several malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle.
The resulting backdoor access can then be used to deploy additional remote access trojans, maintain persistence, collect sensitive information, and move deeper into compromised environments.
More Than 30,000 Devices Compromised
The joint advisory estimates that the campaign has compromised at least 30,000 devices across more than 100 countries.
The attackers have also targeted cryptocurrency wallets, with more than 7,000 wallets reportedly affected.
Investigators estimate that victims have lost at least $10.71 million in cryptocurrency.
The campaign demonstrates how North Korean threat actors continue to combine social engineering with malware distribution to target individuals who have access to valuable cryptocurrency assets, corporate systems, source code, and development infrastructure.
WaterPlum and North Korean IT Worker Operations
The advisory also identifies links between WaterPlum activity and North Korean IT worker operations.
Some WaterPlum operators reportedly work as IT professionals performing web development and system design tasks for organizations.
Investigators identified a laptop farm operated by a facilitator in Japan and said the infrastructure was subsequently dismantled.
WaterPlum actors have also used online communication platforms to communicate with developers in the United States and Japan.
Facilitators in Japan, the United States, and other countries have reportedly helped establish and operate laptop farms that allow remote management of devices used for employment.
Risks to Organizations
The campaign presents a broader risk than cryptocurrency theft.
When developers are compromised, attackers can potentially gain access to corporate systems, cloud infrastructure, development environments, source code, credentials, and software development pipelines.
The joint advisory noted that successful infections can provide attackers with opportunities for espionage, intellectual property theft, and additional lateral movement within corporate networks.
Stolen identity documents and personal information can also potentially be abused by North Korean IT workers to impersonate victims and generate foreign currency.
North Korean IT Worker Scheme Expands
The Contagious Interview campaign operates alongside a broader North Korean IT worker scheme designed to generate revenue by securing employment under false identities.
The scheme has increasingly incorporated artificial intelligence to create fictitious identities and support recruitment activities.
Threat actors have reportedly targeted companies in the United States, Japan, and other countries while using VPN services to make their connections appear to originate from different geographic locations.
The operations can involve fraudulent resumes, fabricated identities, remote access arrangements, and intermediaries who help North Korean workers bypass employment restrictions.
Recruitment of Western Proxies Through Discord
Researchers from Silent Push recently identified a North Korean IT worker using Discord to recruit individuals who could act as proxies during job interviews.
The Discord server, named "Mouse Review," was reportedly used to recruit individuals in the United States, European Union, and Latin America.
The proposed arrangement involved the proxy acting as the public-facing candidate while the North Korean operator handled technical work remotely.
The advertised role reportedly offered payments to individuals who participated in communications and job interviews.
The arrangement was designed to help bypass sanctions, geographic restrictions, Know Your Customer requirements, and corporate compliance checks.
Silent Push assessed that the financial arrangement could provide approximately 35% of the earnings to the proxy while the North Korean IT worker retained approximately 65%.
How the Attack Works
The Contagious Interview campaign typically follows a social engineering driven infection chain:
- The attacker approaches a developer or IT professional with a fake job opportunity.
- The victim is encouraged to communicate with the supposed recruiter.
- The attacker provides a coding test or technical assessment.
- The victim downloads or executes malicious project files or software.
- Malware establishes an initial foothold on the device.
- Additional payloads are deployed to maintain persistence.
- Attackers collect credentials, browser information, cryptocurrency data, and other sensitive information.
- The compromised system may then be used to access additional corporate resources.
Why Developers Are High-Value Targets
Developers and IT professionals often have access to sensitive infrastructure that extends far beyond their individual computers.
A compromised developer workstation may provide access to:
- Source code repositories
- Cloud environments
- CI/CD pipelines
- API credentials
- SSH keys
- Cryptocurrency wallets
- Corporate communication platforms
- Internal development systems
- Database credentials
- Software deployment infrastructure
This makes developer endpoints an attractive target for threat actors seeking both financial gain and access to larger organizations.
Key Takeaway
The Contagious Interview campaign highlights the continued use of fake employment opportunities as an initial access technique by North Korean threat actors.
The combination of social engineering, malware, cryptocurrency theft, identity fraud, and fraudulent IT worker operations creates risks for both individual professionals and organizations.
Developers should independently verify recruiters and employers, avoid executing unknown code as part of unsolicited technical assessments, and use isolated environments for testing unfamiliar projects.
Organizations should also strengthen controls around developer endpoints, cryptocurrency assets, source code repositories, cloud credentials, and remote access infrastructure.