- North Korean threat actors compromised 30,000 devices across 100+ countries and stole from over 7,000 cryptocurrency wallets, netting at least $10.71 million.
- The Contagious Interview campaign targets Web3 developers via fake job offers on platforms like LinkedIn, deploying malware such as BeaverTail and OtterCookie.
- Operators are linked to North Korea’s IT worker scheme, which now uses Discord to recruit proxies in the U.S., E.U., and Latin America to bypass sanctions.
The North Korean threat actors behind the Contagious Interview campaign have breached at least 30,000 devices across 100 countries and drained funds or credentials from over 7,000 cryptocurrency wallets, according to a joint cybersecurity advisory. Targeting individual web designers and blockchain specialists, the group is estimated to have stolen at least $10.71 million in cryptocurrency.
The campaign, first exposed by Palo Alto Networks Unit 42, has been active since 2022. Threat actors pose as recruiters on social media, instructing targets to complete coding tests that trigger a multi-step infection chain deploying malware families like BeaverTail and OtterCookie.
Once backdoor access is established, the attackers deliver remote access trojans for persistent data exfiltration. The advisory notes that some operators also work as North Korean IT workers under the 313 General Bureau, using laptop farms for remote device management.
Meanwhile, the North Korean IT worker scheme is expanding to Discord for recruiting proxies. Silent Push identified a fake job ad on a server named “Mouse Review” seeking U.S., E.U., and Latin American citizens to attend interviews and bypass sanctions. The ad offers a 35% financial split to proxies, with payments of $3,000 to $5,000 per job secured.
Facilitators are instructed to let the North Korean worker remotely access their screen during live coding challenges. Stolen ID images are also used to impersonate victims and generate foreign currency, as detailed in a Silent Push report.
According to Kudelski Security, primary targets appear to be the U.S. and Japan, with threat actors using VPN services like Astrill VPN for exit nodes. The broader campaign enables espionage and intellectual property theft within corporate environments.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
