HomeSecurityContagious Interview: 30,000 devices breached & crypto stolen

Contagious Interview: 30,000 devices breached & crypto stolen

A large-scale cyber campaign focused on fake job postings is revealing a new and particularly dangerous dimension of attacks against technology professionals. The perpetrators behind the Contagious Interview, which is linked to North Korea, are said to have compromised at least 30,000 devices in more than 100 countries, while gaining access to more than 7,000 cryptocurrency wallets.

Article Image: Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

Total losses from cryptocurrency theft are estimated at at least $10.71 million, according to a joint warning from cybersecurity and intelligence agencies from the US, Japan, Australia and Germany.

Web3 developers and experts in the spotlight

The campaign focuses primarily on programmers, web designers, software engineers , and professionals active in the cryptocurrency, blockchain, and Web3.

See also: Contagious Interview: Attack with 338 malicious npm packages

Perpetrators approach potential victims by presenting attractive job opportunities, often through professional networking platforms and online communication services. The bait is a supposed interview or technical assessment, which is presented as a necessary stage for recruitment.

In reality, however, the “test” can be the first step in a multi-layered attack. The technical assessment is used as a vehicle to convince the candidate to download files, execute code, or install tools containing malware.

From a fake interview to a full-blown breach

Contagious Interview is a long-standing operation that has been documented since at least 2022 and was originally identified by Palo Alto Networks' Unit 42.

After the initial communication, the perpetrators attempt to lead the victim into a chain of actions that can result in the installation of different malware families. Among them, BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy and StoatWaffle have been recorded.

Once the malware is installed, attackers can gain remote access functions, monitor device activity, and search for stored credentials, files, and information related to digital wallets.

The role of WaterPlum and "laptop farms"

The agencies that issued the warning link the activity to the WaterPlum, while pointing to possible connections with North Korean IT workers.

One of the most worrying aspects concerns the use of so-called “laptop farms”, i.e. facilities in which a large number of laptops can be located in a different country and controlled remotely. Such infrastructures can be used to make an employee appear to be a professional located in the area where they are needed, while the real work is carried out from elsewhere.

Researchers have also identified cases where the same or similar technical indicators were used to access laptop farms and for activities related to cryptocurrency exchanges.

Contagious Interview: 30,000 devices breached & crypto stolen

The risk doesn't stop at cryptocurrency theft

Hacking a developer's device can have far greater consequences than losing money or an account.

See also: Ghost Campaign: 7 malicious npm packages steal crypto wallets

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

If the victim works for a technology company, access to their computer could provide attackers with a potential entry point into the corporate environment. From there, they can search for internal systems, source code, corporate documents, API keys, passwords, and other sensitive data.

Authorities warn that such successful infections can be exploited for espionage, intellectual property theft, and lateral movement within corporate networks. At the same time, stolen images and identity information can be used to create convincing fictitious profiles.

The second side: Fake IT workers

This activity is linked to a broader North Korean program involving the placement of IT workers in foreign companies with false credentials.

The goal is not necessarily a direct cyberattack. In some cases, an employee may gain legitimate access to corporate systems and then exploit that access for financial gain or intelligence gathering.

The use of artificial intelligence now enhances this activity, as it can be used to create fictitious resumes, profiles, photos, and other material that makes a fake identity more convincing.

New technique: "Representatives" in interviews

Even more worrying is the emergence of proxy hiring, where a real person acts as the “face” of a North Korean worker.

Silent Push detected related activity on a Discord, where people from the US, Europe, and Latin America were being sought to participate in recruitment processes on behalf of other individuals.

In some scenarios, the actual technician was reportedly able to the remotely access intermediary's computer during a live technical test and perform the programming tasks themselves.

Contagious Interview - SecNews.gr

This practice further complicates identity checks, as the person appearing on camera and answering questions is not necessarily the same person who will ultimately work for the company.

What companies should pay attention to

The new reality requires stricter controls on remote hiring. Companies should be wary of technical challenges that require installing unknown software, executing code, or providing access to systems.

At the same time, identity verification should not be limited to a resume or a video call. Candidate background checks, secure environments for coding tests, limited access rights, and constant monitoring can significantly reduce risk.

See also: Adobe Campaign Classic: Critical CVSS 10.0 vulnerability allows unauthenticated code execution (CVE-2026-48449)

The Contagious Interview case ultimately shows how cyberattacks and recruitment fraud can merge into a single enterprise. A seemingly innocent job posting can launch an attack that ends up stealing cryptocurrency, breaching corporate networks, or even installing a fake employee within the company itself.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS