Contagious Interview campaign compromises 30,000 devices

North Korea-linked campaign reaches 30,000 devices
A joint advisory from cybersecurity and intelligence agencies in Japan, the United States, Australia and Germany says the Contagious Interview campaign has compromised at least 30,000 devices in more than 100 countries. The operators are estimated to have stolen at least $10.71 million in cryptocurrency and funds or account credentials from more than 7,000 cryptocurrency wallets.
The campaign primarily targets individual web designers, engineers and specialists working in cryptocurrency, blockchain and Web3. The broader cybersecurity community tracks the activity under several names, including WaterPlum, CL-STA-0240, DeceptiveDevelopment, Famous Chollima, UNC5342 and Void Dokkaebi.
Recruitment lures lead to multi-stage malware delivery
Active since at least 2022, Contagious Interview approaches software developers and IT professionals while posing as prospective employers or recruiters. Actors establish contact on social platforms such as LinkedIn and present lucrative roles before asking targets to complete a job assessment or coding test.
That assessment starts a multi-step infection chain. The advisory identifies malware families including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy and StoatWaffle. The access obtained can then be used to deploy remote access trojans for persistence and data exfiltration.
The agencies warn that a successful infection can reach beyond the individual developer. It can provide a path into the organization that employs the victim, creating opportunities for espionage, intellectual-property theft and lateral movement. Stolen identity images may also be used by North Korean IT workers to impersonate victims and generate foreign currency.
IT worker operations overlap with the threat activity
Investigators assess that WaterPlum and some North Korean IT workers, also known as PurpleDelta or Wagemole, operate under the 313 General Bureau of the Munitions Industry Department. The clusters have in some cases used the same IP addresses to access laptop farms and to apply for roles at Japanese cryptocurrency exchanges.
Authorities identified and dismantled a laptop farm operated by a facilitator in Japan. WaterPlum has also used online chat platforms to communicate with US and Japanese developers, while enablers in Japan, the US and other countries helped establish and manage laptop farms for remote device access.
Proxy recruitment adds a compliance risk
Separately, Silent Push reported a North Korean IT worker using a Discord server called Mouse Review to recruit people in the US, the EU and Latin America as interview proxies. The offer promised $3,000 to $5,000 to facilitators and described remote help during live coding challenges.
For businesses, recruitment and developer assessment workflows are now part of the attack surface. Teams should independently verify recruiters and employers, keep coding exercises in isolated environments, and give employees a clear route to report suspicious job approaches before credentials, code or corporate devices are exposed.

