$ techbeacon▋
CVE & Exploits

North Korean‑linked ‘Contagious Interview’ hack hits 30,000 devices, steals $10.7 million in crypto

North Korean‑linked ‘Contagious Interview’ hack hits 30,000 devices, steals $10.7 million in crypto

A joint advisory released this week warns that a North Korean state‑sponsored group behind the so‑called Contagious Interview operation has infiltrated at least 30,000 computers in more than 100 countries, extracting funds or credentials from over 7,000 cryptocurrency wallets and amassing roughly $10.71 million in stolen assets.

The campaign relies on a deceptive “interview” lure: victims receive what appears to be a legitimate request for a video or audio interview, often from a purported media outlet or recruitment agency. When the target clicks the attached link or opens a seemingly benign document, a custom remote‑access trojan is installed, granting the attackers persistent control. Once inside, the malware scans for cryptocurrency wallet files, private keys, and exchange login details, forwarding the data to command‑and‑control servers before exfiltrating the assets to a series of anonymised wallets.

Security researchers note that the operation builds on a pattern of North Korean cyber‑crime that has intensified over the past few years. Groups such as Lazarus have repeatedly turned to cryptocurrency as a primary revenue stream, exploiting the relative anonymity and ease of cross‑border transfers. The scale of Contagious Interview—targeting tens of thousands of endpoints and compromising thousands of wallets—places it among the most extensive crypto‑focused espionage efforts attributed to the regime.

Victims span a broad spectrum, from individual investors and small‑scale traders to employees of fintech firms and cryptocurrency exchanges. The advisory highlights that the majority of compromised devices were ordinary personal computers and smartphones, underscoring how the campaign sidesteps high‑value corporate networks in favor of sheer volume. Because crypto transactions are irreversible and often routed through mixers, recovering the stolen $10.7 million is expected to be extremely difficult, leaving affected users with limited recourse.

Experts urge organizations and private users to adopt layered defenses: verify interview requests through independent channels, keep software patched, employ multi‑factor authentication for exchange accounts, and store private keys offline whenever possible. Law‑enforcement agencies in several jurisdictions have been notified, but attribution and prosecution remain challenging given the geopolitical context. Analysts anticipate that the group may evolve the technique, potentially integrating more sophisticated social‑engineering vectors or targeting emerging blockchain platforms as the crypto ecosystem continues to expand.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related