North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews
Joint report from Japan, US, Germany, and Australia says Contagious Interview stole $10 million in crypto NK operatives used fake personas, companies, and “laptop farms” to infiltrate 30,000+ devices in 100 countries Agencies urge vigilance: verify applicants’ details, check IPs, validate certifications, and watch for crypto‑based payments North Korean threat actors behind the infamous “Contagious Interview” campaign have so far compromised more than 30,000 devices across 100 countries, and have robbed around 7,000 people of their hard-earned cryptocurrencies.
The theft has brought more than $10 million to the North Korean government, a new report jointly released by law enforcement agencies in Japan, the United States, Germany, and Australia has found.
Fake everything Contagious Interview is a hacking campaign running for almost four years now.
Sometimes it’s also called Operation DreamJob .
The cybersecurity community in general attributes it to the government of North Korea, although more precise attribution is rather difficult.
Some researchers believe it is being done by the Lazarus Group, one of the largest and most influential state-sponsored actors around.
Others believe different groups are involved, labeled DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, or TAG-121.
Contagious Interview leverages the lack of skilled workers in the West to infiltrate organizations, steal sensitive data and ultimately, money.
North Korean operatives would create entire fake personas on social media such as LinkedIn, and would apply to hundreds, if not thousands, of job ads across IT, healthcare, and other industries.
The personas are carefully crafted, using a mix of legitimate information stolen in data breaches (names, SSNs, addresses), and AI-generated images, video, and audio.
If hired, the operatives would use their access to infect organizations with malware , steal login credentials and different access, and exfiltrate sensitive files and cryptos.
The operation works the other way around, as well.
Crooks would create fake companies and fake job positions, and would then reach out to their targets to offer lucrative positions on exciting projects.
As part of the hiring process, the candidates would be asked to download and work on code which, unknown to them, was malicious.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.