North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews | Tech Radar
Overview
News, deals, reviews, guides and more on the newest computing gadgets
Start exploring exclusive deals, expert advice and more
Details
Unlock and manage exclusive Techradar member rewards.
Unlock instant access to exclusive member features.
Get full access to premium articles, exclusive features and a growing list of member rewards.
North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Joint report from Japan, US, Germany, and Australia says Contagious Interview stole $10 million in crypto
NK operatives used fake personas, companies, and “laptop farms” to infiltrate 30,000+ devices in 100 countries
Agencies urge vigilance: verify applicants’ details, check IPs, validate certifications, and watch for crypto‑based payments
North Korean threat actors behind the infamous “Contagious Interview” campaign have so far compromised more than 30,000 devices across 100 countries, and have robbed around 7,000 people of their hard-earned cryptocurrencies.
The theft has brought more than $10 million to the North Korean government, a new report jointly released by law enforcement agencies in Japan, the United States, Germany, and Australia has found.
Contagious Interview is a hacking campaign running for almost four years now. Sometimes it’s also called Operation Dream Job.
The cybersecurity community in general attributes it to the government of North Korea, although more precise attribution is rather difficult.
Some researchers believe it is being done by the Lazarus Group, one of the largest and most influential state-sponsored actors around.
This North Korean recruitment scam was so convincing it even fooled Google
North Korea expands fraudulent job resumes to target marketing, sales, and medical sector
Amazon flags North Korean hacker group as being behind the surge in open source supply chain attacks
Others believe different groups are involved, labeled Deceptive Development, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, Purple Bravo, or TAG-121.
Contagious Interview leverages the lack of skilled workers in the West to infiltrate organizations, steal sensitive data and ultimately, money. North Korean operatives would create entire fake personas on social media such as Linked In, and would apply to hundreds, if not thousands, of job ads across IT, healthcare, and other industries.
The operation works the other way around, as well. Crooks would create fake companies and fake job positions, and would then reach out to their targets to offer lucrative positions on exciting projects. As part of the hiring process, the candidates would be asked to download and work on code which, unknown to them, was malicious. The North Koreans would then pivot to their targets’ current employers, resulting in the same outcome.
One of the ways organizations in the West are trying to combat this issue is by being mindful of the IP address and the location from which their employees are logging on. To work around this challenge, the attackers have set up “laptop farms” - facilities located abroad (usually in countries that don’t have that strict limitations, but are still NK-friendly, such as China), hosting hundreds of laptops. They would then access their targets’ networks through these laptops, to make sure their actual location is never revealed.
‘A candidate who was hostile from day one never produces that baseline’: Nation states spies applying for legit jobs are hard to spot
Security experts targeted by fake crypto conference in scam to hand over details
Nord VPN warns of fake Ryanair, Emirates, Qatar Airways websites used to spread malware
The primary targets are individual web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web 3 technologies, it was said. Businesses should be wary when they receive numerous applications in a short time, for a position where there are usually very few applicants.
“If possible, verify that IP addresses generally match the applicant’s claimed residence,” the report states. “Carefully check all contact information. Calling an applicant’s phone number may reveal the number is out of service.”
The agencies also warned that trying to get hired is often a group effort: “Even if a single individual appears to be applying, multiple people may be collaborating behind the scenes, inflating the perceived skill set.” Therefore, businesses should verify certifications by checking registration numbers and, in case of any inconsistencies, should ask for detailed explanations.
Asking personal details about the applicant’s hometown, weather, or hobbies, is often a good way to spot a scammer. Finally, it was said that North Korean IT workers tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person’s name.
Contagious Interview has been ongoing for roughly four years now, and during that time it evolved significantly. Security agencies warn that changes to the standard practice could happen at any time, and that the variations to the theme should be expected.
➡️ Read our full guide to the best antivirus
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with Life Lock
- Best for mobile: Mc Afee Mobile Security
Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, Io T, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
MSI Cyborg A15 Ryzen 7 creative laptop gets a $250 price cut at Newegg and I can't find it cheaper anywhere else
mac OS 27 has broken Mission Control — and there are other reported bugs too
This TP-Link Deco Wi-Fi 7 mesh system eliminates internet dead zones with speeds up to 4.3 Gbps
Watch England vs Sri Lanka 2026 T20 series: Live Streams
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
- News, deals, reviews, guides and more on the newest computing gadgets
- Start exploring exclusive deals, expert advice and more
- Unlock and manage exclusive Techradar member rewards
- Unlock instant access to exclusive member features
- Get full access to premium articles, exclusive features and a growing list of member rewards



