North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices in over 100 countries and stolen funds or credentials from more than 7,000 cryptocurrency wallets, causing at least $10.71 million in losses. The operation targets developers and crypto professionals through fake job offers, delivering malware and using the WaterPlum IT worker network to enable credential theft, espionage, and proxy hiring. #ContagiousInterview #WaterPlum #BeaverTail #InvisibleFerret #Discord #LinkedIn
Keypoints
- Contagious Interview has infected at least 30,000 devices across more than 100 countries.
- The campaign has stolen credentials or funds from over 7,000 cryptocurrency wallets.
- Victims are lured through fake job offers aimed at developers and crypto specialists.
- The infection chain deploys malware such as BeaverTail, InvisibleFerret, and other payloads.
- WaterPlum and North Korean IT workers also use proxy hiring and laptop farms to support their operations.
Read More: https://thehackernews.com/2026/09/contagious-interview-campaign.html