news.mlab.sh
Back to the feed
threat-intel

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

High
Summary

North Korean cyber actors, operating under various groups like WaterPlum and linked to IT workers, are running a sophisticated campaign targeting individual web designers, engineers, and crypto professionals worldwide. They impersonate job recruiters on platforms like LinkedIn and Discord to lure victims into completing coding tests that trigger a malware infection chain, leading to credential theft and remote access. The campaign is designed to steal cryptocurrency and facilitate espionage, with a significant portion of the operation focused on using foreign nationals as proxies to bypass sanctions and hiring restrictions, resulting in over $10.71 million in stolen crypto.

North Korean cyber actors, primarily operating under groups like WaterPlum and linked to IT workers (PurpleDelta/Wagemole), are engaged in a long-running campaign – Contagious Interview – targeting individual web designers, engineers, and cryptocurrency professionals globally. The campaign began in 2022 and continues to evolve, leveraging social media platforms like LinkedIn and Discord to impersonate job recruiters and entice victims into completing coding tests.

These tests trigger a multi-step infection chain, deploying various malware families including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle. Once initial access is gained, the adversary uses remote access trojans to establish persistent access and exfiltrate stolen data. The primary goal is to steal cryptocurrency and facilitate espionage within targeted organizations.

The campaign is deeply intertwined with an established North Korean IT worker scheme, which has roots dating back to the 1960s when North Korea dispatched labor abroad to earn foreign currency. This scheme has expanded to include construction, textiles, and restaurant services across Russia, China, the Gulf, and Africa.

Currently, the operation relies heavily on AI to generate fictitious identities and expand its global reach. Facilitators in Japan, the U.S., and other countries are employed to set up and manage laptop farms for remote device management. The scheme utilizes VPN services like Astrill VPN and Mullvad to obtain exit nodes in countries like the U.S. and Japan, allowing the actors to bypass geographic restrictions and compliance checks.

Recent analysis reveals a Discord server named "Mouse Review" is being used to spread a fake job recruitment scam, hiring individuals in the U.S., the E.U., and Latin America to act as proxies and attend job interviews. The AI-generated job advertisement promises a lucrative split (35% to the proxy, 65% to the North Korean IT Worker) for handling communications and completing coding tasks remotely.

This scheme is designed to bypass sanctions, KYC controls, and regional hiring restrictions, with the North Korean IT workers serving as financial and identity mules. The operation has already resulted in the theft of over $10.71 million in cryptocurrency. The North Korean IT worker's primary goal is proxy hiring, using Western or Latin American citizens as the ‘face’ and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions.

Read the full article at The Hacker News