How a Fake Interview Campaign Hijacked 30,000 Computers and Millions in Crypto

·
Listen to this article~5 min
How a Fake Interview Campaign Hijacked 30,000 Computers and Millions in Crypto

A North Korean hacking campaign, posing as job interviews, compromised 30,000 devices globally, stealing from over 7,000 crypto wallets and netting $10.71 million. Web designers and crypto specialists were primary targets.

Let's talk about something that feels like it's straight out of a spy thriller, but it's very, very real. You know how we all get those job interview requests? The ones that promise exciting opportunities and big paychecks? Well, imagine one of those emails not being a door to a new career, but a trapdoor that empties your digital wallet. That's exactly what just happened on a massive scale. According to a new joint cybersecurity advisory, North Korean threat actors ran a sophisticated operation called the **Contagious Interview campaign**. And the numbers are staggering. They've compromised at least **30,000 devices** spread across more than 100 countries. From those devices, they managed to siphon funds or steal the login credentials for over **7,000 cryptocurrency wallets**. The total haul? A cool **$10.71 million** in cryptocurrency. Gone. ### Who Was Targeted in This Campaign? This wasn't a random spray-and-pray attack. The hackers were hunting with precision. Their primary targets were specific professionals they knew would have valuable access or knowledge: - Individual web designers - Software engineers and developers - Specialists working directly in the cryptocurrency and blockchain space Think about it. These are the exact people who might manage crypto wallets for clients, work on DeFi platforms, or have access to private keys for various projects. It's a classic case of going where the money is, or more accurately, where the digital keys to the vault are kept. The campaign's name, "Contagious Interview," tells you everything about its method. It spread by posing as legitimate job interview requests. ### How the "Interview" Trap Worked So, how does a fake interview lead to a compromised computer? It's all about social engineering—manipulating people, not just code. Here's the likely playbook: 1. **The Lure:** A target receives a professional-looking email or message about a lucrative job opportunity. The role is perfectly tailored to their skills in web design, engineering, or crypto. 2. **The Hook:** The "recruiter" asks them to review a document, often a job description or a technical test. This file isn't a simple PDF. It's loaded with malicious code. 3. **The Infection:** Once opened, that file installs malware on the device. This malware could be a keylogger, stealing every password typed. It could be remote access software, giving the hackers control. Or it could specifically scan for and exfiltrate cryptocurrency wallet files and seed phrases. 4. **The Theft:** With access granted, the attackers quietly drain wallets or copy credentials to access accounts later. By the time the victim realizes, the digital funds have vanished into the blockchain's anonymity. It's frighteningly effective because it preys on hope and professional ambition. Who wouldn't open a document for a potential dream job? As one security analyst recently noted, "The most dangerous malware doesn't exploit a flaw in software; it exploits the trust of the person using it." ### What This Means for Digital Security This incident is a massive wake-up call, especially for freelancers and professionals in tech and finance. Your skills make you a target. Here are a few immediate takeaways: - **Verify, then trust.** Be intensely skeptical of unsolicited job offers, especially those that require you to download or open files immediately. - **Isolate sensitive work.** Consider using a separate, locked-down device or environment for managing cryptocurrency assets. Don't mix daily browsing and email with high-value financial activities. - **Assume you're a target.** If you work in crypto, web3, or high-value tech, operate with that mindset. Update your software, use strong, unique passwords, and enable multi-factor authentication everywhere it's offered. The $10.71 million loss is a stark reminder. In the digital age, our professional identities and our financial assets are directly linked. Protecting one means vigilantly guarding the other. This campaign didn't just steal money; it weaponized the very process of seeking a better job. That's a new level of audacity, and it demands a new level of caution from all of us.