Fake Coding Tests Give North Korean Operators a Foothold on 30,000 Devices
North Korea's Contagious Interview used fake coding tests to compromise 30,000 devices and 7,000 crypto wallets, causing $10.71M in losses.
Illustrative image generated with AI
Recruitment lures conceal a global intrusion operation
North Korean threat actors have compromised at least 30,000 devices in more than 100 countries through fraudulent job offers and weaponized employment assessments. The operation, known as Contagious Interview, has also affected more than 7,000 cryptocurrency wallets and caused estimated losses of at least $10.71 million.
The campaign has operated since at least 2022. Its principal targets are individual software engineers, web designers, and specialists working in cryptocurrency, blockchain, and Web3.
Operators contact potential victims through professional networking and social-media platforms, including LinkedIn. They impersonate recruiters or employers, advertise attractive positions, and invite candidates to complete coding exercises or technical assessments.
The assignment is the attack vector. Running associated software or completing the supplied project can start a multi-stage infection that installs backdoors and remote-access tools. The attackers can then steal credentials and cryptocurrency, exfiltrate files, maintain access, or use the developer’s computer as an entry point into an employer’s environment.
A joint advisory described by the reporting organizations connects the activity to North Korean actors. Researchers track overlapping parts of the operation under numerous names, including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, WaterPlum, and Contagious Interview.
Palo Alto Networks Unit 42 was the first organization identified as exposing the campaign.
Malware turns a coding exercise into persistent access
Contagious Interview does not depend on one malware family or a single delivery method. The associated toolset includes:
- BeaverTail
- InvisibleFerret
- FlexibleFerret
- GolangGhost
- PylangGhost
- OtterCookie
- RATatouille
- OtterCandy
- StoatWaffle
The infection process begins only after the operators have established enough trust to persuade a candidate to interact with the assessment. That social stage is critical because software developers routinely download repositories, install dependencies, execute unfamiliar code, and troubleshoot projects supplied by other people.
A malicious task can therefore resemble ordinary recruitment work. The victim may be asked to review a project, fix a bug, add a feature, or demonstrate proficiency with a development framework. The available information does not identify a universal file type, programming language, repository service, or command used across all infections.
Once executed, the campaign’s malware can establish backdoor access, deploy remote-access trojans, preserve persistence, and remove information from the device. Cryptocurrency wallets and account credentials are direct targets, but the operation has broader intelligence value.
A developer’s workstation may contain source code, cloud tokens, private repository credentials, internal conversations, signing material, browser sessions, and access to production or development systems. If the device is connected to an employer’s network, the initial personal compromise can become a corporate intrusion involving lateral movement, espionage, or intellectual-property theft.
Identity documents and personal images are also useful to the operators. Stolen material can support impersonation by North Korean IT workers seeking employment under another person’s identity.
Wallet theft is only one measure of the damage
The known statistics show substantial financial impact: more than 7,000 cryptocurrency wallets were affected through theft or compromise of wallet and account credentials. Confirmed estimated losses total at least $10.71 million.
Those figures do not capture the full potential cost. The 30,000 compromised devices may include systems belonging to independent contractors, employees working remotely, or developers with privileged access to business infrastructure.
Companies in cryptocurrency and Web3 face particularly concentrated exposure. Their employees are attractive both because they may hold digital assets personally and because their work can provide access to wallets, smart-contract code, trading platforms, customer information, or operational credentials.
Conventional endpoint counts may also obscure the relationship between victims. A single infected developer laptop could expose multiple client environments, code repositories, or cloud accounts. Conversely, one victim could have several affected wallets.
It is not known how many of the compromised endpoints led to secondary access inside employers. No complete geographic breakdown, victim list, or malware-family distribution has been disclosed.
WaterPlum overlaps with fraudulent IT-worker activity
The attribution links WaterPlum to parts of North Korea’s wider fraudulent IT-worker program. The workers are also tracked as PurpleDelta or Wagemole.
WaterPlum and the IT-worker operation are assessed to function under the 313 General Bureau of the Munitions Industry Department. This matches an assessment published by DTEX in June 2025.
The two activities are closely connected rather than entirely separate. In some cases, operators used the same IP addresses while accessing laptop farms and applying for jobs at Japanese cryptocurrency exchanges. Some WaterPlum personnel reportedly work as North Korean IT contractors themselves, delivering web design and development services to corporate customers.
Facilitators in Japan, the United States, and other countries operate laptop farms that make computers physically located in the target region available for remote control. This arrangement can make an overseas operator appear to be connecting from an expected location.
One facilitator-managed laptop farm in Japan has been identified and dismantled. Further technical details about that disruption, including the number of devices involved or whether related infrastructure was disabled, are not known.
Infrastructure research published by Kudelski Security in July 2026 identified the United States and Japan as the principal targeting areas. Operators used commercial services including Astrill VPN and Mullvad to create exit points in those countries.
AI and interview proxies weaken identity checks
The wider IT-worker scheme uses false identities to secure foreign employment and generate revenue for North Korea. Artificial intelligence increasingly assists with creating fictional personas and producing recruitment material at scale.
This model extends a much older foreign-currency strategy. North Korea sent workers abroad during the 1960s and 1970s, initially for logging in the Soviet Far East. The practice later expanded into construction, textiles, and restaurants across Russia, China, the Gulf, and Africa.
Digital work removes many physical constraints, but employers still conduct video interviews, identity checks, live coding tests, and regional compliance reviews. The operators address those controls by recruiting local proxies.
Silent Push recently identified a North Korean IT worker using a Discord server called “Mouse Review” to seek participants in the United States, European Union, and Latin America. The advertised compensation ranged from $3,000 to $5,000 when a proxy helped secure a job.
Under the proposed arrangement, the proxy would appear on camera and continue the interview while giving the remote operator real-time access to the screen. The North Korean worker could then complete live programming challenges while the proxy acted as the visible candidate.
The reported revenue split assigns 35% to the proxy and 65% to the North Korean worker. This structure turns foreign nationals into identity, employment, and payment intermediaries while helping the operator bypass sanctions, know-your-customer checks, geographic restrictions, and hiring controls.
Defenders should treat assessments as untrusted code
No vendor patch can resolve this campaign because the initial weakness is human trust combined with routine developer behavior. No universal detection signature, malware hash set, or complete infrastructure list has been disclosed.
Organizations can still reduce exposure by changing how technical assessments are handled:
- Run candidate projects only in isolated, disposable environments without access to corporate networks, password stores, cryptocurrency wallets, SSH keys, cloud credentials, or source repositories.
- Prohibit employment assessments from requiring remote-control software, unusual package installation, disabled security tools, or access to personal financial accounts.
- Verify recruiters and job openings through independently obtained corporate contact details rather than links supplied during the conversation.
- Treat dependencies, build scripts, package manifests, and pre-installation hooks in assessment projects as potentially hostile.
- Investigate unexpected remote-access tools, new persistence mechanisms, unusual outbound connections, and credential access following a coding exercise.
- Revoke active sessions and rotate exposed credentials if a developer executed a suspicious assessment.
- Review whether an affected machine could reach repositories, cloud platforms, internal messaging systems, development environments, or production services.
- Strengthen candidate verification with independent identity checks rather than relying only on video presence, IP geolocation, or a successful live coding test.
Potential victims should isolate suspect devices before conducting a broader credential reset from a known-clean system. Cryptocurrency access, browser sessions, developer tokens, email accounts, and employer credentials all require review.
The dismantled Japanese laptop farm removed one piece of supporting infrastructure, not the campaign’s underlying recruitment model. Contagious Interview remains effective because it places malicious execution inside an activity developers are expected to perform: proving that they can work with unfamiliar code.
Sources
This article is an original reworking based on the sources below.
