Skip to main content
Emerging ThreatsMalware & Ransomware

North Korea Targets 30,000 Devices in Global Crypto Heist

Modern office interior with rows of computer workstations and people working.

At least 30,000 devices in more than 100 countries have been compromised and at least $10.71 million in cryptocurrency siphoned from victims, according to a new joint cybersecurity advisory.

Scale and attribution: a multinational advisory names North Korean actors

Cybersecurity and intelligence agencies from Japan, the United States, Australia, and Germany issued a joint advisory describing the Contagious Interview campaign, attributing the activity to North Korean threat actors and a broader set of clusters tracked under names including CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum. The advisory says the campaign has compromised at least 30,000 devices and stolen credentials or funds from over 7,000 cryptocurrency wallets, with a minimum estimated theft of $10.71 million in cryptocurrency.

Modus operandi: fake hiring, coding tests, and a multi-stage infection chain

The campaign targets individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies by approaching them on professional social platforms under the pretext of lucrative job offers. As the advisory summarized, the adversary "conducts cyber attacks by infiltrating unsuspecting job seekers' computer networks, harvesting sensitive information, and stealing cryptocurrency."

After initial contact and rapport-building, the threat actors instruct targets to complete a job assessment or coding test. That exercise triggers a multi-step infection chain that deploys a range of malware families, including BeaverTail, InvisibleFerret, FlexibleFerret, GolangGhost, PylangGhost, OtterCookie, RATatouille, OtterCandy, and StoatWaffle. The advisory says backdoor access is abused to deliver remote access trojans that enable persistent access and data exfiltration.

WaterPlum, PurpleDelta/Wagemole, and links to the 313 General Bureau

The advisory links WaterPlum and some North Korean IT workers—also referred to as PurpleDelta or Wagemole—to the 313 General Bureau of the Munitions Industry Department, corroborating a June 2025 assessment published by DTEX. It notes that the two clusters are "deeply intertwined," and in some cases used the same IP addresses when accessing laptop farms and applying for positions at Japanese cryptocurrency exchanges. The agencies also reported that a laptop farm operated by a facilitator in Japan has been identified and dismantled.

IT worker scheme expands: Discord proxies, AI-created identities, and payment incentives

The advisory documents how the long-running Contagious Interview campaign complements an expanding North Korean IT worker scheme that generates hard currency for the regime. That program now increasingly relies on artificial intelligence to craft fictitious identities and to expand global activity. A July 2026 analysis of related infrastructure by Kudelski Security said primary targets appear to be the United States and Japan and that the actors obtained exit nodes in those countries using VPN services such as Astrill VPN and Mullvad.

Separate reporting cited in the advisory—by Silent Push—identified a recruitment scam operating on a Discord server named "Mouse Review." The scam targets individuals in the U.S., the EU, and Latin America to act as proxies and attend job interviews, explicitly designed to "get around sanctions, geographic blocks, and compliance checks." The AI-generated job advertisement reads in part: "YOUR ROLE IS SIMPLE, BUT CRUCIAL. You handle communications and interviews. I handle all technical work behind the scenes. You get paid consistently for your communication." Facilitators who secure jobs were offered between $3,000 and $5,000, with the ad promising a financial split of "35% to the proxy, 65% to the North Korean IT Worker."

What this means for Web3 developers, cryptocurrency exchanges, and national cyber agencies

  • Web3 developers: Individuals in design, engineering, and blockchain roles are singled out as primary targets; the attacks begin with convincing recruiting outreach and exploit routine hiring practices such as coding tests to trigger malware deployment.
  • Cryptocurrency exchanges and employers: The advisory highlights cases where the adversary used the same infrastructure to apply to Japanese cryptocurrency exchanges and to access laptop farms; stolen ID images are also used to impersonate victims and generate foreign currency, exposing hiring and KYC processes to fraud.
  • National cyber agencies and investigators: The advisory represents a coordinated multinational response and ties the activity to known clusters and to the 313 General Bureau, while also reporting the dismantling of a Japan-based laptop farm—an operational disruption that agencies explicitly documented.

The Contagious Interview campaign combines social engineering, commodity and custom malware, and an international proxying operation that now includes AI-produced identities and recruitment via platforms such as Discord. The advisory establishes both a long timeline—operations dating back to at least 2022—and a broad, practical playbook: lure, test, infect, and monetize through credential theft, wallet siphoning, and impersonation. The next concrete markers to watch will be whether similar laptop farms reappear, whether the identified VPN exit-node techniques scale beyond the U.S. and Japan, and how hiring platforms and exchanges respond to these specific, documented abuses.

Original advisory and reporting