North Korean threat actors orchestrated a sprawling social engineering campaign that compromised 30,000 devices across more than 100 countries and drained cryptocurrency from over 7,000 wallets, netting attackers $10.71 million in stolen funds.

The Contagious Interview campaign targeted individual web designers, engineers, and cryptocurrency specialists through deceptive job recruitment tactics. Threat actors posed as recruiters or hiring managers, luring victims with fake job offers at legitimate technology companies. Once victims engaged with the fraudulent interview process, attackers deployed malware designed to steal cryptocurrency wallet credentials and other sensitive account information.

The campaign reflects an evolution in North Korean cyber tactics. Rather than targeting large organizations through infrastructure attacks, this operation focused on individual technical professionals with access to valuable digital assets. The scale of the operation demonstrates the operational sophistication of North Korean threat groups, which routinely combine social engineering with malware delivery to maximize victim engagement and minimize detection.

Security researchers documented the campaign across multiple vectors. Victims received fake job interview materials, video calls conducted through legitimate platforms, and eventually malware-laden files disguised as assessment tools or coding challenges. The technical sophistication lay not in the malware itself but in the social engineering foundation that made victims willing to execute files on their own systems.

The cryptocurrency theft represents the campaign's primary financial objective. Attackers specifically sought wallet credentials and seed phrases from victims, granting direct access to digital assets. The $10.71 million total theft across 7,000 compromised wallets suggests average losses per wallet of roughly $1,500, though distribution likely varied significantly. Some victims lost substantially more.

Geographically dispersed targeting across 100-plus countries indicates the threat actors cast wide nets through job boards and professional networking platforms. LinkedIn remains a frequent vector for such recruitment fraud. North Korean threat groups, including those attributed to the Lazarus Group and its offshoots, regularly use these platforms to identify and contact technical professionals.

The advisory naming Contagious Interview did not specify which North Korean entity orchestrated the campaign, though historical patterns suggest connections to state-sponsored cyber operations. North Korea has increasingly pivoted toward cryptocurrency theft as traditional nation-state espionage yields diminishing returns. The hermit nation faces harsh economic sanctions, making theft operations a direct revenue source for government operations.

Organizations should implement email filtering rules that flag suspicious recruitment communications, particularly those requesting immediate malware downloads or installation of unfamiliar software. Cryptocurrency professionals require additional security awareness training focused on social engineering attacks. Individual contractors and freelancers should verify job offers through official company channels before engaging further with recruiters.

The campaign underscores a persistent threat landscape where nation-state actors regularly target individuals rather than exclusively pursuing institutional access. Defenders cannot rely solely on corporate security infrastructure when threats operate at the personal device level.