Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Announces Security Deal With Denmark and Greenland

    September 21, 2026

    Putin’s party wins supermajority in Russia’s parliamentary election | Elections News

    September 21, 2026

    Young people’s Pip claims for ADHD and autism ‘rising fastest in affluent areas’ | Society

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Announces Security Deal With Denmark and Greenland
    • Putin’s party wins supermajority in Russia’s parliamentary election | Elections News
    • Young people’s Pip claims for ADHD and autism ‘rising fastest in affluent areas’ | Society
    • Claim up to $95 today from Apple’s Siri AI settlement – here’s how
    • BigCommerce alerts merchants of data breach linked to Ribon apps
    • Jordi Visser: Why AI Agents Make The BTC Bull Case
    • Embracing the Equinox – NASA Science
    • For wild rivers like the Karnali, Nepal’s disaster is a warning and an answer (commentary)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 21, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.

    The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. In all, the threat actors are estimated to have plundered at least $10.71 million worth of cryptocurrency from victims.

    The alert comes courtesy of cybersecurity and intelligence agencies from Japan, the U.S., Australia, and Germany. The activity is tracked by the broader cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum.

    The cyber threat group “conducts cyber attacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency,” the alert said.

    It’s suspected that both WaterPlum and some North Korean IT workers (aka PurpleDelta or Wagemole) operate under the 313 General Bureau of the Munitions Industry Department, corroborating a June 2025 assessment from DTEX. What’s more, the two clusters are said to be deeply intertwined, in some cases using the same IP addresses when accessing laptop farms and applying for positions at Japanese cryptocurrency exchanges.

    Contagious Interview, first exposed by Palo Alto Networks Unit 42, is a long-running campaign that has been underway since at least 2022, targeting software developers and IT professionals across the wild by posing as prospective employers and recruiters, and approaching them on social media platforms like LinkedIn under the pretext of lucrative job offers.

    Cybersecurity

    Once initial rapport is established, the threat actors instruct targets to complete a job assessment or coding test, triggering a multi-step infection chain that leads to the deployment of various malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle.

    The backdoor access afforded is then abused by the adversary to deliver remote access trojans for enabling persistent access and data exfiltration.

    “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” the agencies said, adding a laptop farm operated by a facilitator in Japan has been identified and dismantled.

    Furthermore, WaterPlum has been observed using online chat platforms to communicate with U.S. and Japanese developers, while employing enablers in Japan, the U.S., and other countries to set up and manage laptop farms for remote device management.

    “Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments,” the agencies noted. “Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency.”

    IT Worker Threat Expands to Discord for Recruiting Proxies

    Complementing North Korea’s offensive cyber capabilities is the infamous IT worker scheme, which is tasked with generating illicit revenue for the regime by landing jobs in Western companies and elsewhere under false identities. The operation is also known for increasingly relying on artificial intelligence (AI) to craft fictitious identities and expand its activities globally.

    Sekoia, in its overview of North Korea’s cyber operations, described the IT worker program as an adaptation of an established practice that involved the “dispatch of North Korean labor abroad to earn foreign currency dates to the 1960s and 1970s, beginning with logging in the Soviet Far East before broadening into construction, textiles and restaurant services across Russia, China, the Gulf and Africa.”

    Cybersecurity

    According to a July 2026 analysis of the internal infrastructure linked to the threat, Kudelski Security said the primary targets appear to be the U.S. and Japan, with the threat actors using VPN services like Astrill VPN and Mullvad to obtain exit nodes in these countries.

    In a report published last week, Silent Push said it identified a North Korean IT worker spreading a fake job recruitment scam via a Discord server named “Mouse Review,” specifically hiring individuals based in the U.S., the E.U., and Latin America to act as proxies and attend job interviews so as to get around sanctions, geographic blocks, and compliance checks.

    The AI-generated job advertisement claims: “YOUR ROLE IS SIMPLE, BUT CRUCIAL. You handle communications and interviews. I handle all technical work behind the scenes. You get paid consistently for your communication.”

    Facilitators who end up securing a job are eligible for anywhere between $3,000 and $5,000, the ad continues. “For live coding challenges, I can remotely access your screen and complete coding tasks while you continue the conversation smoothly.”

    “The North Korean IT worker’s primary goal is proxy hiring, using Western or Latin American (LATAM) citizens as the ‘face’ and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions,” Silent Push said. “The job ad scam offers a financial incentive split (35% to the proxy, 65% to the North Korean IT Worker) to incentivize foreign nationals to serve as financial and identity mules.”

    10.71M campaign Compromises Contagious Crypto devices Interview Steals
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    BigCommerce alerts merchants of data breach linked to Ribon apps

    Robinhood CEO Says Crypto Will Beat Sports at Prediction Markets’ Own Game

    CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast

    WordPress Click2Shell flaw lets hackers execute PHP on the server

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

    Google Hit With $463 Million Fine for EU Location Data Rule Breach

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Announces Security Deal With Denmark and Greenland

    September 21, 2026

    Putin’s party wins supermajority in Russia’s parliamentary election | Elections News

    September 21, 2026

    Young people’s Pip claims for ADHD and autism ‘rising fastest in affluent areas’ | Society

    September 21, 2026

    Claim up to $95 today from Apple’s Siri AI settlement – here’s how

    September 21, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Announces Security Deal With Denmark and Greenland

    September 21, 2026

    Putin’s party wins supermajority in Russia’s parliamentary election | Elections News

    September 21, 2026

    Young people’s Pip claims for ADHD and autism ‘rising fastest in affluent areas’ | Society

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.