A North Korea-linked operation known as “Contagious Interview” posed as recruiters and employers to lure developers into completing “job assessments” or “coding tests,” which led to malware infection. Investigators say at least 30,000 devices were compromised across 100+ countries, and funds/credentials were stolen from over 7,000 crypto wallets, totaling at least $10.71M in losses.
How the attack worked
The Contagious Interview campaign relies on a simple but effective pretext: a recruiter or prospective employer reaches out on a platform like LinkedIn with a lucrative job offer. Once rapport is established, the target is asked to complete a job assessment or coding test. That assessment is where the infection chain begins, ultimately compromising the victim's device. Investigators tie the campaign to North Korean actors and report at least 30,000 compromised devices across more than 100 countries, with over $10.71 million in cryptocurrency stolen from more than 7,000 wallets.
A related scheme observed on Discord took the deception further. A fake job ad recruited people to act as interview 'proxies,' letting someone else handle the actual technical work behind the scenes while the recruited person fronted the conversation. In some cases, the scheme even involved remote access to a proxy's screen during live coding challenges, allowing the real operator to complete tasks unnoticed.
Why it succeeded
This campaign succeeds because it exploits normal hiring behavior. Developers, designers, and blockchain specialists are accustomed to completing coding tests and technical assessments as part of a legitimate interview process. That familiarity lowers suspicion when a similar request arrives from an unverified contact. The financial incentive of a 'lucrative role' also encourages targets to move quickly rather than pause to verify the recruiter or company.
The Discord-based proxy scheme succeeded for a different reason: it offered steady pay for what looked like low-effort communication work, while quietly asking participants to enable identity misrepresentation and remote access, red flags that can be easy to overlook when framed as a simple job.
What to watch for
- Unsolicited outreach for a high-paying job from an unknown recruiter
- Pressure to download or run unfamiliar assessment files or code as part of an interview
- Recruiting conversations that shift quickly from normal hiring talk to running executable 'tests'
- Job offers that explicitly ask someone to front interviews while another person does the technical work
- Requests for remote screen access during a coding challenge
Building resistance
Organizations and individuals in software development, design, and crypto/Web3 roles should independently verify recruiters and companies before engaging further, and should never run assessment materials from unverified sources outside an isolated environment. Recruiting and talent acquisition teams should be aware that a compromised developer can become an entry point into their employer's broader network, enabling data theft or lateral movement. Treating any interview process involving identity misrepresentation or remote access requests as an immediate red flag can help stop this type of attack before it leads to compromise.
Key findings
- Campaign attributed to North Korean actors compromised at least 30,000 devices in 100+ countries.
- Victims included web designers, engineers, and specialists in cryptocurrency/blockchain/Web3; at least $10.71M in crypto was stolen from 7,000+ wallets.
- Attackers posed as recruiters/prospective employers on social platforms like LinkedIn and used a job-offer pretext to push “job assessments”/“coding tests.”
- Successful infections enabled persistent access and data exfiltration, and could be used to infiltrate companies employing targeted developers.
- A related DPRK IT-worker scheme used Discord to recruit “proxies” to front interviews and bypass sanctions/KYC/region checks.
Who’s being targeted
- Commonly targeted roles: Engineering / Software Development, Web/UX Designers, Blockchain/Crypto/Web3 Teams, Recruiting / Talent Acquisition, IT / Security Awareness.
- Affected industries: Software development / IT services, Cryptocurrency / Web3, Cryptocurrency exchanges.
- Attack channels: linkedin, discord.
- Impersonated: Prospective employer / recruiter (fake hiring manager), Recruiter posting a job opportunity in a Discord server.
Red flags to watch for
- Unsolicited outreach for a “lucrative job offer” from an unknown recruiter
- Pressure to run unfamiliar assessment materials or code as part of an interview
- Recruiting conversation quickly shifts to downloading/running “tests” instead of standard hiring steps
- Offer explicitly proposes deception (someone else doing the technical work)
- Financial incentive to bypass identity checks and compliance processes
- Request for remote access/screen control during live coding challenges
Frequently asked questions
What is the Contagious Interview campaign?
It is a North Korea-linked operation where attackers pose as recruiters or employers on platforms like LinkedIn, luring developers into completing fake job assessments or coding tests that trigger malware infection.
How many devices and victims were affected?
At least 30,000 devices across more than 100 countries were compromised, with funds or credentials stolen from over 7,000 cryptocurrency wallets, totaling at least $10.71 million in losses.
Who is targeted by this scam?
The campaign targets software developers, web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 who might be approached with lucrative job offers.
What is the Discord proxy interview scheme?
A related DPRK IT-worker scheme used a Discord server to recruit people to act as the visible 'face' during job interviews while the actual technical work was done remotely by someone else, helping bypass sanctions and identity checks.
Read the video transcript
Imagine losing your crypto and infecting your work laptop… just because you ran a “coding test” from LinkedIn. A North Korea-linked campaign called “Contagious Interview” hit 30,000 devices by posing as recruiters on LinkedIn, then pushing job assessments that silently installed malware and drained over $10 million from 7,000 crypto wallets. Here’s the twist: once they trust you, the chat jumps straight to “Run this test app” or “Execute this code locally,” or on Discord, “I’ll do the coding while you just sit in the interview and I’ll remote into your screen.” That’s not recruiting, that’s a backdoor into you and your company. If a recruiter you don’t know asks you to download or run any assessment package, stop and verify: close the chat, find the company’s real careers page, and contact them through that instead.