Threat Intelligence

North Korean 'Contagious Interview' Scam Hits 30,000 Devices, Steals Over $10 Million in Crypto

The Hacker News · 22 Sept 2026
Key Takeaway Job seekers and hiring teams in the tech and crypto space should treat unsolicited recruiter contact and coding test files with caution, and avoid running unknown code from job assessments on personal or work devices.

A joint cybersecurity advisory from agencies in Japan, the US, Australia and Germany has revealed that North Korean threat actors behind the 'Contagious Interview' campaign have compromised at least 30,000 devices across more than 100 countries. The group has stolen funds or credentials from over 7,000 cryptocurrency wallets, amounting to at least $10.71 million in losses.

The campaign primarily targets web designers, engineers and specialists working in cryptocurrency, blockchain and Web3 fields. Attackers pose as recruiters on platforms like LinkedIn, offering enticing job opportunities before instructing victims to complete a coding test or job assessment. This step triggers a multi-stage infection process that installs various malware families designed to steal data and cryptocurrency, and grant attackers ongoing remote access to compromised systems.

The activity, tracked under multiple names including DeceptiveDevelopment and Famous Chollima, has been active since at least 2022. Investigators believe the group is linked to North Korea's 313 General Bureau of the Munitions Industry Department, and that its infrastructure overlaps with North Korean IT worker fraud schemes exposed in earlier research.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.