North Korean threat actors linked to the “Contagious Interview” campaign have compromised more than 30,000 devices across 100 countries and stolen cryptocurrency from about 7,000 people, according to a report jointly released by law enforcement agencies in Japan, the United States, Germany, and Australia.
TechRadar reports that the theft generated more than $10 million for the North Korean government. The campaign has operated for almost four years and is also known as Operation DreamJob. Cybersecurity researchers generally attribute it to North Korea, although precise attribution remains difficult. Some researchers link it to the Lazarus Group, while others identify groups including DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, and TAG-121.
The operators create fake personas on LinkedIn using stolen personal information and AI-generated images, video, and audio. They may apply for hundreds or thousands of jobs, especially in IT, healthcare, cryptocurrency, blockchain, and Web3. In other cases, they create fake companies and positions, then ask applicants to download malicious code during the hiring process.
The report says attackers also use overseas “laptop farms” to access networks while concealing their real locations. Agencies warned that applications from multiple collaborators, unverifiable certifications, inconsistent contact details, and requests for cryptocurrency payments to accounts in other people’s names can indicate the campaign. They expect the operation to continue changing.
Comments
0No comments yet. Be the first to comment.