Massive North Korean Cyber Campaign Compromises 30,000 Devices Worldwide in Sophisticated "Contagious Interview" Web3 Heist

A sweeping joint cybersecurity advisory issued by intelligence and defense agencies across the United States, Japan, Australia, and Germany has revealed the true global scale of the notorious "Contagious Interview" campaign. Orchestrated by state-sponsored North Korean threat actors, the sprawling operation has successfully compromised at least 30,000 devices across more than 100 countries. Investigators report that the attackers have systematically siphoned funds and credentials from over 7,000 cryptocurrency wallets, plundering an estimated $10.71 million in digital assets.
The campaign specifically targets software engineers, web designers, and blockchain or Web3 specialists. By weaponizing the recruitment process, these threat actors have turned standard hiring pipelines into vector pathways for mass malware deployment, corporate espionage, and financial theft.
The Evolution and Anatomy of the "Contagious Interview" Operation
First identified and analyzed in detail by Palo Alto Networks Unit 42, the Contagious Interview campaign has been running continuously since at least 2022. The operation relies heavily on social engineering via professional networking platforms like LinkedIn. Attackers pose as legitimate recruiters, venture capitalists, or tech startup founders, dangling lucrative remote job offers to entice high-value IT and cryptocurrency professionals.
Once initial rapport and trust are established under the guise of an authentic hiring process, targets are directed to complete a technical assessment or coding test. Downloading and executing these test environments triggers a complex, multi-stage infection chain. Rather than relying on a single piece of software, the actors deploy an extensive array of malware families designed to establish persistent footholds, harvest credentials, and bypass security controls.
Among the primary payloads utilized in these attacks are BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle. These tools act as conduits for delivering advanced remote access trojans (RATs), granting the hackers deep visibility into corporate networks and private personal environments alike.

Security researchers note that the malware is engineered to target both Windows and macOS ecosystems, ensuring maximum adaptability depending on the developer’s tech stack. Once a machine is compromised, the attackers quickly locate and extract browser-saved credentials, session cookies, and private keys belonging to cryptocurrency wallets, leading to immediate financial losses for the victims.
An Intertwined Web of State-Sponsored Threat Clusters
The global cybersecurity community tracks the actors behind these campaigns under a dizzying array of designations, including WaterPlum, PurpleBravo, CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, UNC5342, and Void Dokkaebi.
According to recent threat intelligence assessments—such as those published by DTEX in June 2025—key operational clusters like WaterPlum and distinct factions of North Korean IT workers (often referred to as PurpleDelta or Wagemole) operate under the direct oversight of the 313 General Bureau of the Munitions Industry Department. This bureau serves as a core administrative body managing state-directed revenue generation through cyber operations.
Investigations have revealed that these distinct operational clusters are deeply intertwined. In multiple instances, analysts have observed overlapping infrastructure, including shared IP addresses used to manage automated laptop farms and apply for positions at prominent cryptocurrency exchanges, particularly in Japan.
The use of laptop farms—physical arrays of computers managed remotely via proxy services and enablers—allows North Korean operatives to bypass geolocation restrictions and identity verification protocols. Law enforcement agencies recently scored a major victory by identifying and dismantling one such major laptop farm operated by a local facilitator in Japan, though the broader network remains active and adaptive.
Expanding the Scheme: Proxy Recruiting and Discord Scams
Beyond direct malware deployment and cryptocurrency heists, North Korean cyber capabilities have expanded to incorporate elaborate proxy-hiring schemes. These operations are explicitly designed to generate hard currency for the regime by placing state-backed IT workers into legitimate remote engineering roles at Western and international companies using stolen or synthetic identities.

A July 2026 report by Kudelski Security highlighted that North Korean operatives heavily utilize virtual private network (VPN) providers such as Astrill VPN and Mullvad to obscure their true locations, routing their traffic through exit nodes in the United States and Japan.
Further compounding the threat, recent research from Silent Push uncovered that North Korean IT actors have begun infiltrating community chat platforms, such as a Discord server named "Mouse Review," to recruit foreign nationals from the United States, Europe, and Latin America. These local proxies are hired to act as the "face" and legal identity for remote job interviews, successfully bypassing compliance checks, identity verification (KYC) controls, and regional sanctions.
Job advertisements distributed through these channels utilize artificial intelligence to craft convincing narratives. One typical AI-generated ad recovered by investigators reads: "YOUR ROLE IS SIMPLE, BUT CRUCIAL. You handle communications and interviews. I handle all technical work behind the scenes. You get paid consistently for your communication."
To incentivize participation, the scammers offer a financial split—typically 35% of the earnings to the foreign national proxy and 65% retained by the North Korean handler—along with promises of screen-sharing solutions during live technical assessments to handle complex coding tasks in real-time.
Historical Context of North Korean Labor Exploitation
Security analysts point out that modern cyber-enabled revenue generation is simply the digital evolution of an old state strategy. According to an overview of North Korean cyber capabilities by Sekoia, the practice of dispatching state-controlled labor abroad to secure foreign currency dates back to the 1960s and 1970s.
Initially, this involved logging operations in the Soviet Far East before broadening into global construction, textiles, and restaurant services across Russia, China, the Gulf states, and Africa. As international sanctions tightened and global digitalization accelerated, Pyongyang pivoted its workforce model from physical labor markets to the global digital economy, transforming software development and cryptocurrency operations into state-sponsored cash cows.

Broader Implications and Corporate Risks
The implications of the Contagious Interview campaign extend far beyond direct financial theft from individual developers. Joint intelligence advisories emphasize that a successful endpoint infection provides WaterPlum and affiliated actors with a crucial bridgehead into corporate environments.
Once inside a developer’s workstation, threat actors gain opportunities for industrial espionage, intellectual property theft, and lateral movement across corporate enterprise networks. Furthermore, stolen identification documents and biometric images harvested during the recruitment process are regularly recycled to generate fake identities, perpetuating future cycles of fraud and foreign currency generation.
Cybersecurity agencies urge organizations, particularly those in the Web3, blockchain, and financial technology sectors, to rigorously vet recruitment pipelines. Companies are advised to implement strict endpoint detection and response (EDR) solutions, verify the identities of remote contractors through live, multi-factor video interviews, and exercise extreme caution when reviewing unsolicited coding assessments or third-party build tools. As state-sponsored threat actors continue to refine their social engineering tactics with artificial intelligence and proxy networks, safeguarding the software supply chain remains one of the premier challenges for global digital security.





