Threats · 14h ago
A joint advisory from Japan, the U.S., Australia, and Germany says the North Korean Contagious Interview campaign has compromised at least 30,000 devices in more than 100 countries, drained funds or credentials from over 7,000 crypto wallets, and stolen at least $10.71 million. The activity is tracked as CL-STA-0240, DeceptiveDevelopment, Famous Chollima, Tenacious Pungsan, UNC5342, and related names.
The campaign starts with fake recruiters and job assessments on social platforms such as LinkedIn. Once a target runs the coding test or interview material, the malware chain lands and gives the operators access to the device and wallet data; in parallel, some of the same infrastructure and handlers are tied to proxy-hire activity that can move money through unwitting workers and help evade sanctions.
For organizations that recruit developers or review remote coding tests, the exposure is not only endpoint compromise. The hiring process itself becomes part of the attack surface, and the laundering layer can keep working even after one infected machine is cleaned up.
1 source covering this story
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
North Korean Contagious Interview campaign compromised 30,000 devices and stole at least $10.71 million in cryptocurrency.
Part of the PlainSec briefing for 2026-09-22