Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
AI Summary
North Korean threat actors associated with the Contagious Interview campaign have compromised over 30,000 devices across more than 100 countries since at least 2022, targeting software developers and IT professionals in cryptocurrency, blockchain, and Web3 sectors. The attackers pose as recruiters on platforms like LinkedIn, offering fake job opportunities that lead to multi-stage malware infections. Malware families deployed include BeaverTail, InvisibleFerret, and RATatouille, enabling credential theft, cryptocurrency theft, and lateral movement into corporate networks. A related operation uses Western proxies recruited via Discord to bypass sanctions and identity checks, with North Korean IT workers using AI-generated identities to secure remote jobs and steal funds.
AI-extracted · verify before operational use
Extracted Entities 8 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | mouse-review[.]discord[.]gg | Details → |