“Contagious Interview” Job Scam Hits 30K Devices

The Hacker News · High sophistication
Last updated September 22, 2026

A North Korea-linked operation known as “Contagious Interview” posed as recruiters and employers to lure developers into completing “job assessments” or “coding tests,” which led to malware infection. Investigators say at least 30,000 devices were compromised across 100+ countries, and funds/credentials were stolen from over 7,000 crypto wallets, totaling at least $10.71M in losses.

How the attack worked

The Contagious Interview campaign relies on a simple but effective pretext: a recruiter or prospective employer reaches out on a platform like LinkedIn with a lucrative job offer. Once rapport is established, the target is asked to complete a job assessment or coding test. That assessment is where the infection chain begins, ultimately compromising the victim's device. Investigators tie the campaign to North Korean actors and report at least 30,000 compromised devices across more than 100 countries, with over $10.71 million in cryptocurrency stolen from more than 7,000 wallets.

A related scheme observed on Discord took the deception further. A fake job ad recruited people to act as interview 'proxies,' letting someone else handle the actual technical work behind the scenes while the recruited person fronted the conversation. In some cases, the scheme even involved remote access to a proxy's screen during live coding challenges, allowing the real operator to complete tasks unnoticed.

Why it succeeded

This campaign succeeds because it exploits normal hiring behavior. Developers, designers, and blockchain specialists are accustomed to completing coding tests and technical assessments as part of a legitimate interview process. That familiarity lowers suspicion when a similar request arrives from an unverified contact. The financial incentive of a 'lucrative role' also encourages targets to move quickly rather than pause to verify the recruiter or company.

The Discord-based proxy scheme succeeded for a different reason: it offered steady pay for what looked like low-effort communication work, while quietly asking participants to enable identity misrepresentation and remote access, red flags that can be easy to overlook when framed as a simple job.

What to watch for

  • Unsolicited outreach for a high-paying job from an unknown recruiter
  • Pressure to download or run unfamiliar assessment files or code as part of an interview
  • Recruiting conversations that shift quickly from normal hiring talk to running executable 'tests'
  • Job offers that explicitly ask someone to front interviews while another person does the technical work
  • Requests for remote screen access during a coding challenge

Building resistance

Organizations and individuals in software development, design, and crypto/Web3 roles should independently verify recruiters and companies before engaging further, and should never run assessment materials from unverified sources outside an isolated environment. Recruiting and talent acquisition teams should be aware that a compromised developer can become an entry point into their employer's broader network, enabling data theft or lateral movement. Treating any interview process involving identity misrepresentation or remote access requests as an immediate red flag can help stop this type of attack before it leads to compromise.

Key findings

  • Campaign attributed to North Korean actors compromised at least 30,000 devices in 100+ countries.
  • Victims included web designers, engineers, and specialists in cryptocurrency/blockchain/Web3; at least $10.71M in crypto was stolen from 7,000+ wallets.
  • Attackers posed as recruiters/prospective employers on social platforms like LinkedIn and used a job-offer pretext to push “job assessments”/“coding tests.”
  • Successful infections enabled persistent access and data exfiltration, and could be used to infiltrate companies employing targeted developers.
  • A related DPRK IT-worker scheme used Discord to recruit “proxies” to front interviews and bypass sanctions/KYC/region checks.

Who’s being targeted

  • Commonly targeted roles: Engineering / Software Development, Web/UX Designers, Blockchain/Crypto/Web3 Teams, Recruiting / Talent Acquisition, IT / Security Awareness.
  • Affected industries: Software development / IT services, Cryptocurrency / Web3, Cryptocurrency exchanges.
  • Attack channels: linkedin, discord.
  • Impersonated: Prospective employer / recruiter (fake hiring manager), Recruiter posting a job opportunity in a Discord server.

Red flags to watch for

  • Unsolicited outreach for a “lucrative job offer” from an unknown recruiter
  • Pressure to run unfamiliar assessment materials or code as part of an interview
  • Recruiting conversation quickly shifts to downloading/running “tests” instead of standard hiring steps
  • Offer explicitly proposes deception (someone else doing the technical work)
  • Financial incentive to bypass identity checks and compliance processes
  • Request for remote access/screen control during live coding challenges
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Contagious Interview campaign?

It is a North Korea-linked operation where attackers pose as recruiters or employers on platforms like LinkedIn, luring developers into completing fake job assessments or coding tests that trigger malware infection.

How many devices and victims were affected?

At least 30,000 devices across more than 100 countries were compromised, with funds or credentials stolen from over 7,000 cryptocurrency wallets, totaling at least $10.71 million in losses.

Who is targeted by this scam?

The campaign targets software developers, web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 who might be approached with lucrative job offers.

What is the Discord proxy interview scheme?

A related DPRK IT-worker scheme used a Discord server to recruit people to act as the visible 'face' during job interviews while the actual technical work was done remotely by someone else, helping bypass sanctions and identity checks.

Read the video transcript

Imagine losing your crypto and infecting your work laptop… just because you ran a “coding test” from LinkedIn. A North Korea-linked campaign called “Contagious Interview” hit 30,000 devices by posing as recruiters on LinkedIn, then pushing job assessments that silently installed malware and drained over $10 million from 7,000 crypto wallets. Here’s the twist: once they trust you, the chat jumps straight to “Run this test app” or “Execute this code locally,” or on Discord, “I’ll do the coding while you just sit in the interview and I’ll remote into your screen.” That’s not recruiting, that’s a backdoor into you and your company. If a recruiter you don’t know asks you to download or run any assessment package, stop and verify: close the chat, find the company’s real careers page, and contact them through that instead.

Similar attacks

Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
DPRK Poses as Recruiters to Malware IT Pros

DPRK Poses as Recruiters to Malware IT Pros

Australian and allied agencies warned that North Korean-linked actors are impersonating recruiters and fake AI/crypto/NFT companies to lure IT professionals into a hiring process that installs malware. The goal is to steal sensitive information and drain cryptocurrency wallets, with reporting…

September 22, 2026
Fake Job Interview Repo Tricks DevOps Into Malware

Fake Job Interview Repo Tricks DevOps Into Malware

North Korea–linked "Jade Sleet" used job interview-style coding projects to trick developers into running malicious infrastructure code. The lure involved GitHub repositories that contained a weaponized Terraform file, leading to downloads from attacker-controlled domains and installation of macOS…

September 21, 2026
Fake Recruiters Hit Job Seekers With Malware Files

Fake Recruiters Hit Job Seekers With Malware Files

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from…

September 18, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026