# North Korean ‘Contagious Interview’ Malware Steals $10.7M in Crypto and Compromises 30,000 Devices Worldwide

*Monday, September 21, 2026 at 6:07 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-21T18:07:33.045Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 9/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18478.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: A long‑running North Korean operation using fake job offers and coding tests has infected more than 30,000 devices in over 100 countries and siphoned at least $10.71 million in cryptocurrency. The ‘Contagious Interview’ campaign shows how Pyongyang’s hackers are turning ordinary career opportunities into a global revenue stream that helps blunt sanctions.

North Korea has quietly turned the desperation and ambition of job seekers into a global hacking channel, compromising tens of thousands of machines and converting stolen credentials into hard currency.

Security researchers say the so‑called “Contagious Interview” campaign, linked to North Korean operators, has compromised more than 30,000 devices across 100‑plus countries and stolen at least $10.71 million in cryptocurrency. The scheme uses fake job offers and coding tests to trick targets into running malware, which then drains funds or captures credentials from over 7,000 crypto wallets, according to a detailed analysis published on 21 September.

The mechanics are deceptively mundane. Targets are approached with what appear to be legitimate job opportunities, often tailored to developers and IT professionals. As part of the hiring process, they’re asked to complete coding tests or download interview materials. Hidden inside those files are malware loaders that, once executed, give the attackers a foothold on the victim’s machine. From there, the operation fans out: stealing authentication tokens, browser credentials and direct access to crypto wallets if they are accessible.

What distinguishes this campaign is its scale and persistence. Infecting more than 30,000 devices is not a smash‑and‑grab run; it suggests a sustained operation that has evolved over time, refining lures and tools while avoiding wholesale shutdown. The geographic spread—over 100 countries—means the victims likely include individuals and organizations in both advanced economies and developing states, across multiple regulatory environments.

For the people on the receiving end, the losses are deeply personal. Crypto holdings vanish from wallets they thought were safely tucked behind passwords and seed phrases. Developers and freelancers who live from contract to contract find that the very outreach they hoped would advance their careers has instead emptied their savings and exposed their machines to further compromise. Some may never know North Korea was behind the theft.

Strategically, this is about more than cybercrime. North Korea is heavily sanctioned and cut off from most formal financial channels. Crypto theft, cyber‑enabled bank fraud and illicit IT work have become core components of how Pyongyang earns foreign currency. Each successful campaign like Contagious Interview helps fund the regime’s missile and nuclear programs, purchase imports and maintain internal patronage networks.

For governments trying to squeeze North Korea, that creates a moving target. Traditional sanctions focus on banks, shipping, mining and arms. Here, the money flows through thousands of small thefts and compromised accounts, often routed through mixers, decentralized exchanges and jurisdictions with limited enforcement capacity. By the time investigators piece together that a series of drained wallets are linked to a job‑offer scam, the funds have typically vanished into harder‑to‑trace channels.

For companies, especially in tech and finance, the campaign raises uncomfortable questions about how well they protect employees from targeted social engineering that arrives through professional networks rather than corporate email. A single developer infected at home can unwittingly bring compromised code or stolen credentials into the workplace, turning a personal loss into a corporate breach.

North Korea doesn’t need to hack banks if it can hack the people who build and use the tools that now hold real value.

Key indicators to watch next include whether law enforcement agencies publicly attribute specific thefts to this campaign and move to sanction associated wallets, whether major hiring platforms tighten verification of recruiters and coding tests, and how quickly exchanges and wallet providers can flag and freeze funds linked to known “Contagious Interview” infrastructure. Those responses will show whether the world treats this as routine cybercrime or as part of a broader confrontation with Pyongyang’s digital revenue machine.
