Fake Job Offers Steal $10.7M from 30,000 Devices

North Korean hackers used fake recruiter profiles to infect 30,000 devices and drain over $10 million in crypto from developers.
Key points
- North Korean hackers stole $10.71 million from over 7,000 crypto wallets via fake job offers.
- The campaign compromised 30,000 devices in 100+ countries by tricking developers into running malicious code tests.
- Authorities link the group to North Korea's IT worker program, which uses stolen identities to infiltrate Western firms.
A coordinated campaign by North Korean threat actors has compromised at least 30,000 devices across more than 100 countries, resulting in the theft of $10.71 million in cryptocurrency. The operation, known as Contagious Interview, primarily targets software developers and blockchain specialists by posing as legitimate recruiters on professional networking sites.
According to a joint advisory from cybersecurity agencies in Japan, the U.S., Australia, and Germany, the attackers successfully drained funds from over 7,000 cryptocurrency wallets. The incident highlights a significant trade-off for remote workers: while digital job offers offer convenience, they also create a vulnerable entry point for sophisticated malware that can persist on a user's machine for months or years.
Recruiters Deploy Malware Through Coding Tests
The attack chain begins with social engineering. Threat actors contact potential victims on platforms like LinkedIn, promising lucrative roles in web design or engineering. Once initial trust is established, the recruiters ask the candidate to complete a coding assessment or job test. This step is the critical failure point, as the test environment is designed to trigger a multi-step infection process that bypasses standard security controls.
Upon execution, the malware deploys various tools, including remote access trojans, to maintain persistent control over the infected device. The catch for the victim is that the system often remains functional, masking the presence of the backdoor. This allows the attackers to exfiltrate sensitive data, steal credentials, and use the device as a springboard to infiltrate the victim's employer's internal networks.
Link to North Korean IT Worker Scheme
The advisory identifies the perpetrators as part of the WaterPlum group, which is deeply intertwined with North Korea's state-sponsored IT worker program. These workers often operate under false identities to secure jobs at Western companies, using their legitimate access to steal intellectual property and generate foreign currency. The campaign has been active since at least 2022, demonstrating a long-term strategy rather than a one-off exploit.
Authorities have noted that the group uses enablers in Japan, the U.S., and other countries to manage laptop farms for remote device control. A recent takedown dismantled one such facility in Japan. The use of AI to craft fictitious identities further complicates detection, as the digital footprints appear increasingly authentic and human-like.
Broader Risks for Corporate Networks
The primary danger lies in the lateral movement capability of the stolen access. Once inside a developer's machine, the attackers can pivot into corporate environments, enabling espionage and intellectual property theft. The stolen identity documents can also be used to impersonate victims for financial fraud, expanding the impact beyond the initial crypto theft. Organizations must treat any unsolicited job offer involving technical testing as a high-risk vector.
The joint advisory from The Hacker News and partner agencies emphasizes that traditional endpoint security is insufficient against such targeted social engineering. The trade-off for companies hiring remote talent is that they must verify the legitimacy of recruitment channels more rigorously. Without this verification, the convenience of global hiring becomes a liability, exposing entire organizations to state-sponsored cyber threats.






