Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
North Korea's Contagious Interview campaign hit 30,000 devices and stole about $10.71 million in crypto.
A joint advisory from agencies in Japan, the United States, Australia, and Germany says North Korean actors behind Contagious Interview, tracked in the alert as WaterPlum, compromised at least 30,000 devices in more than 100 countries. They took funds or credentials from more than 7,000 cryptocurrency wallets, estimated at $10.71 million, mainly targeting developers and Web3 specialists. Since at least 2022, operators pose as recruiters on LinkedIn, send coding tests, and deploy malware including BeaverTail, InvisibleFerret, FlexibleFerret, and OtterCookie, then use remote-access malware for persistence and data theft. Agencies also report overlap with North Korean IT-worker operations, a dismantled laptop farm in Japan, and Discord recruitment of interview proxies.