2026-08-01 · Web3 Security
Since December 2022, North Korean operators have been running fake hiring processes against people who work in crypto, and the payload lands at the moment the candidate does what every technical interview asks of them: clone the repository and run it. The FBI has published a list of warning signs and seized a front company’s domain, US prosecutors have won guilty pleas and indicted four North Korean nationals over the separate scheme in which North Koreans get hired rather than do the hiring, and nobody has been charged over this one.
Case file
| Field | Value |
|---|---|
| Campaign | Contagious Interview |
| Named by | Palo Alto Networks Unit 42, 21 November 2023, tracked as CL-STA-0240 |
| Aliases | DeceptiveDevelopment (ESET), UNC5342 (Google Threat Intelligence Group), PurpleBravo and TAG-121 (Recorded Future), Famous Chollima (CrowdStrike, used by Cisco Talos and Silent Push), Gwisin Gang (DTEX), Tenacious Pungsan (Datadog), DEV#POPPER (Securonix), Void Dokkaebi (Trend Micro), WaterPlum (NTT Security Japan) |
| First observed | December 2022, per Unit 42, Sekoia and Microsoft independently |
| Operating model | Fake recruiter contact, then a coding assessment or bug-fix task the candidate is asked to run locally |
| Malware families | BeaverTail, InvisibleFerret, OtterCookie, GolangGhost, PyLangGhost, JADESNOW, FlexibleFerret, FrostyFerret, Tropidoor |
| Targets | Software developers and, since 2025, non-technical staff at centralised crypto platforms |
| Attribution | DPRK, with vendors split on whether the cluster sits under Lazarus |
| Prosecutions | None. No individual has been charged publicly over Contagious Interview |
| Enforcement to date | FBI seizure of blocknovas.com under a warrant from the Northern District of Texas, April 2025 |
| Aggregate loss figure | Not established. No vendor or agency has published one |
| Status as of 1 August 2026 | Active. Microsoft reported current customer detections in March 2026; Fireblocks disclosed being impersonated in January 2026 |
| Firms and agencies on record | FBI; DOJ; Palo Alto Networks Unit 42; ESET; Google Threat Intelligence Group; Recorded Future; Kaspersky; Sekoia; Cisco Talos; Socket; Silent Push; NTT Security Japan; Huntress; Microsoft; Fireblocks; Chainalysis |
What the record shows
What has the FBI said?
The FBI published public service announcement I-090324-PSA on 3 September 2024. Its first line: “The Democratic People’s Republic of Korea (‘DPRK’ aka North Korea) is conducting highly tailored, difficult-to-detect social engineering campaigns against employees of decentralized finance (‘DeFi’), cryptocurrency, and similar businesses to deploy malware and steal company cryptocurrency.”
The PSA describes teams of operators who pick a target company and then work through its staff: “Teams of North Korean malicious cyber actors identify specific DeFi or cryptocurrency-related businesses to target and attempt to socially engineer dozens of these companies’ employees to gain unauthorized access to the company’s network.” It records that the actors “usually communicate with victims in fluent or nearly fluent English and are well versed in the technical aspects of the cryptocurrency field,” and that they research targets on “professional networking or employment-related platforms” before making contact.
Two of the eight indicators the FBI lists describe this campaign exactly. One is “requests to conduct a ‘pre-employment test’ or debugging exercise that involves executing non-standard or unknown Node.js packages, PyPI packages, scripts, or GitHub repositories.” The other is “requests to run a script to enable call or video teleconference functionalities supposedly blocked due to a victim’s location.”
The PSA’s mitigation list is short and specific. Verify a contact through a second, unconnected channel. Do not store wallet logins, seed phrases or private keys on internet-connected devices. And: “Avoid taking pre-employment tests or executing code on company owned laptops or devices. If a pre-employment test requires code execution, insist on using a virtual machine on a non-company connected device, or on a device provided by the tester.”
Where does the name come from?
Unit 42 published “Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors” on 21 November 2023. It named two campaigns in the same paper and kept them apart.
The first: “We call the first campaign ‘Contagious Interview,’ where threat actors pose as employers (often anonymously or with vague identities) to lure software developers into installing malware through the interview process.” Unit 42 tracked it as CL-STA-0240, dated the start to December 2022, and attributed it “with moderate confidence” to a North Korean state-sponsored actor.
The second: “We call the second campaign ‘Wagemole,’ where threat actors seek unauthorized employment with organizations based in the US and other parts of the world, with potential for both financial gain and espionage.” Wagemole was tracked as CL-STA-0241 and attributed with high confidence. That paper is where the two schemes were first described together and first separated, and the separation has held up.
The 2023 attack chain: an approach through a job platform, an invitation to an online interview, and then, in Unit 42’s words, “the threat actor convinces the victim to download and install an NPM-based package hosted on GitHub.” Unit 42 named the two malware families it found: BeaverTail and InvisibleFerret.
How does the candidate actually get compromised?
ESET published its own analysis on 20 February 2025 under the name DeceptiveDevelopment, and it is the most detailed account of the front end of the attack.
Operators either copy the profile of a real person or build a new one. Early on they used fresh accounts and sent GitHub links over LinkedIn. Later they moved to accounts that look established, with followers and connection history, “others are potentially compromised profiles of real people on the platform, modified by the attackers.” ESET lists the platforms where the approaches happen: LinkedIn, Upwork, Freelancer.com, We Work Remotely, Moonlight and Crypto Jobs List. Silent Push, publishing on 24 April 2025, adds CryptoJobsList, CryptoTask, GetOnBrd, Guru, Intch, Jobatus, SignalHire and Thirdwork.
Then the task. ESET: “The most commonly observed compromise vector consists of the fake recruiter providing the victim with a trojanized project under the guise of a hiring challenge or helping the ‘recruiter’ fix a bug for a financial reward.” The candidate gets the files by direct transfer or a link to GitHub, GitLab or Bitbucket, is asked to add a feature or fix a bug, “and they are instructed to build and execute the project in order to test it, which is where the initial compromise happens.” ESET notes the repositories are usually private, and the candidate is asked for an account ID or email address to be granted access, which also keeps researchers out.
The trojanised projects fall into four kinds: hiring challenges, cryptocurrency projects, games with blockchain functionality, and blockchain gambling. Most are copies of real open-source projects with the malicious line added and the README changed. ESET describes the hiding technique: the operators “place it in an otherwise benign component of the project, usually within backend code unrelated to the task given to the developer, where they append it as a single line behind a long comment.” Word wrap pushes it off screen. ESET points out that GitHub’s own code viewer does not wrap by default, so the line stays invisible in the browser.
Microsoft, in a Microsoft Defender Experts report of 11 March 2026, records a newer variant of the same trick: “when victims open the downloaded package in Visual Studio Code, they are prompted to trust the repository author. If trust is granted, Visual Studio Code automatically executes the repository’s task configuration file, which then fetches and loads the backdoor.” The candidate never types a command.
There is a second route that skips the repository. Unit 42’s report of 9 October 2024 found BeaverTail delivered as installers masquerading as MiroTalk, a real-time video call application, and FreeConference, a conference calling service, compiled for both macOS (MiroTalk.dmg) and Windows (MiroTalk.msi) from a single Qt codebase. When the victim opens it, a fake login window appears while the malware runs behind it. ESET found the download site: mirotalk[.]net, a copy of the legitimate sfu.mirotalk.com.
Sekoia documented a third route on 31 March 2025, a sub-campaign it calls ClickFake Interview. The candidate is sent to a purpose-built interview website, fills in a contact form, answers three questions about cryptocurrency, and is asked to record an introductory video. At that point the camera fails, and the site presents an error with a command to copy and paste. On Windows it is a curl fetching nvidiadrivers.zip, expanding it with PowerShell and running update.vbs. On macOS it is a curl fetching coremedia.sh and running it with nohup. Both end in a Go backdoor Sekoia named GolangGhost. On macOS the chain also drops a component Sekoia and SentinelOne call FrostyFerret, which shows a fake macOS dialog claiming Chrome needs camera access and asks for the system password, then sends the password to Dropbox.
What do these families take?
| Family | Language | First seen | What it takes | Named by |
|---|---|---|---|---|
| BeaverTail | JavaScript, later C++ on Qt | 2023 | Browser wallet extension databases, saved browser logins, the macOS login keychain, Firefox login files, ~/.config/solana/id.json. Downloads the next stage |
Unit 42 |
| InvisibleFerret | Python | 2023 | Keystrokes, clipboard, browser logins and saved card data, arbitrary files over FTP, .env files across whole drives. Installs AnyDesk for persistence |
Unit 42 |
| OtterCookie | JavaScript | September 2024 | Ethereum private keys found in documents and images, clipboard, keystrokes, screenshots, recursive filesystem search | NTT Security Japan |
| GolangGhost | Go | early 2025 | Chrome browsing data, remote shell, file upload and download | Sekoia |
| JADESNOW | JavaScript | February 2025 | Downloader only. Pulls payloads from smart contracts on BNB Smart Chain and Ethereum | Google Threat Intelligence Group |
| Tropidoor | C DLL | November 2024 | Full backdoor. Shares large portions of code with a Lazarus RAT called PostNapTea | AhnLab, ESET |
The detail worth having in front of you is the wallet list. Unit 42’s 2023 paper lists nine Chrome and Edge extension IDs that BeaverTail hunts for, covering MetaMask on both browsers, BNB Chain, Coinbase, TronLink, Phantom, Ronin, Coin98 and Crypto.com, plus the Solana key file at ~/.config/solana/id.json.
By October 2024 the list had grown. Unit 42 states that the Qt build “targets 13 different cryptocurrency wallet browser extensions, compared to only nine wallets previously targeted by the JavaScript variant,” and repeats the figure of 13 in its conclusion. Its own Table 1 lists 12 unique extension IDs, and against its own 2023 list the additions number four (Kaikas, Rabby, Argent X, Exodus) rather than the five the text claims. The row missing from the 2024 table, compared with both the 2023 paper and ESET’s independent list, is Ronin Wallet (fnjhmkhhmkbjkkabndcnnogagogbneec). ESET’s February 2025 list, built separately, runs to 13 IDs because it keeps Ronin. The two firms also disagree on one name: ID jblndlipeogpafnldhgmapagcccfchpi is “Kaikas Wallet” to Unit 42 and “Kaia Wallet” to ESET, which is the same product under its old and new names.
On the second stage, ESET’s module breakdown is the most complete. InvisibleFerret ships as four Python modules: a main loader dropped as .npl in the home directory, a payload module, a browser module, and an AnyDesk module. The payload module runs a keylogger through pyWinHook and a clipboard stealer through pyperclip on Windows, and exposes eight commands to the operator. Two of them matter most. ssh_upload walks directories and pushes files to an FTP server the operator specifies, encrypting anything that is not already a .zip, .rar or .pdf with a hardcoded XOR key of G01d*8@(. ssh_env uploads the whole of Documents and Downloads on Windows plus the contents of drives D to I, or on other systems the entire home directory and /Volumes.
Unit 42 recorded a variant of ssh_env tuned for a different prize: on Windows it “collects .env files from all folders under the following drives: C:\, D:\, E\, F:\, G:\ while ignoring folders named node_modules.” An .env file is where a developer keeps API keys and database credentials.
The browser module copies Chrome, Brave, Opera, Yandex and Edge databases into a temporary folder as LoginData.db and webdata.db, then decrypts them. ESET describes where the decryption keys come from on each platform: the browser’s Local State file on Windows, the secretstorage package on Linux, and the security utility on macOS. A later version added a command called ssh_zcp that collects data from 88 browser extensions and password managers and exfiltrates it over Telegram and FTP.
The AnyDesk module is the only persistence in the chain. It writes a hardcoded password hash, password salt and token salt into AnyDesk’s configuration, and if it cannot edit the files directly it drops a PowerShell script called conf.ps1 in the home directory to do it.
What replaced BeaverTail?
NTT Security Japan’s SOC saw something in November 2024 that was neither BeaverTail nor InvisibleFerret, named it OtterCookie, and published in Japanese in December 2024 and in English on 16 January 2025. The September 2024 version already carried a checkForSensitiveData function that searched for Ethereum private keys by regular expression. The November version moved that work to shell commands sent from the operator, added clipboard theft through the clipboardy library, and used Socket.IO for its command channel.
ESET’s Virus Bulletin conference paper of September 2025, by Matěj Havránek and Peter Kálnai, reads OtterCookie as a replacement rather than an addition: “We believe OtterCookie to be an evolution of BeaverTail, used by some teams within DeceptiveDevelopment instead of the older BeaverTail, while other teams continue using and modifying the original codebase.”
Cisco Talos, publishing on 16 October 2025, found the two merged into one payload and a module nobody had documented. The keylogger uses the Node packages node-global-key-listener and screenshot-desktop, writes keystrokes to 1.tmp and screenshots to 2.jpeg in a temporary subfolder called windows-cache, flushes the keystroke buffer every second and takes a screenshot every four seconds, then uploads both to a C2 server on TCP port 1478. Talos also found a Visual Studio Code extension posing as a hiring onboarding helper with OtterCookie code inside it, though it says it cannot attribute that extension with high confidence.
Google Threat Intelligence Group published the most unusual change on 16 October 2025. Since February 2025 it has tracked UNC5342 using a technique called EtherHiding, “the first time GTIG has observed a nation-state actor adopting this method.” GTIG describes it as “embedding malicious code, often in the form of JavaScript payloads, within a smart contract on a public blockchain like BNB Smart Chain or Ethereum. This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.” The payload is fetched with a read-only eth_call, which leaves no transaction and costs nothing. GTIG’s downloader family for this is JADESNOW, and it delivers a JavaScript build of InvisibleFerret that beacons on port 3306, the default MySQL port. That component “targets cryptocurrency wallets like MetaMask and Phantom, as well as credentials from other sensitive applications like password managers (e.g., 1Password),” zips the result and sends it to a server and a private Telegram chat.
On the economics of running C2 this way, GTIG counted the updates to one contract: “The transaction details show that the contract has been updated over 20 times within the first four months, with each update costing an average of $1.37 USD in gas fees.”
Were there really fake companies?
Silent Push published on 24 April 2025 after pivoting from a BeaverTail C2 domain, lianxinxiao[.]com, to three registered entities used as employers: BlockNovas LLC, SoftGlide LLC and Angeloper Agency.
BlockNovas was the most active. Silent Push confirmed the company was registered in New Mexico through a LegalZoom-affiliated registered agent, with an address of 2001 Augusta Rd, Warrenville, South Carolina, used for the company and for all listed members and organisers, and with two named contacts, “Mehmet Demir” and “Ramon Mckenzie,” both of which Silent Push assesses are fake personas. Google Street View of that address shows no office. The domain was registered in July 2024 through NameCheap. The company had a LinkedIn page listing 14 employees, a Pinterest account, an X account joined in October 2024, and a Calendly link. A BlockNovas subdomain briefly exposed a status dashboard the operators used to monitor four of their own domains. Another subdomain hosted Hashtopolis, a distributed password-cracking manager.
blocknovas.com now serves a seizure notice. Fetched on 1 August 2026, the page reads: “This domain has been seized by the Federal Bureau of Investigation in accordance with a seizure warrant issued by the United States District Court for the Northern District of Texas as part of a law enforcement action against North Korean Cyber Actors who utilized this domain to deceive individuals with fake job postings and distribute malware.” The page tells visitors who interacted with the site to scan their devices, and links to two FBI advisories: the crypto-industry social engineering PSA, and the separate guidance on DPRK IT workers.
Google Threat Intelligence Group names the same three entities in its October 2025 report: “In some instances, they have gone as far as setting up fake company websites and social media presences for entities like ‘BlockNovas LLC,’ ‘Angeloper Agency,’ and ‘SoftGlideLLC’ to appear legitimate.”
Real companies get impersonated too. Fireblocks, the digital-asset infrastructure firm, published on 22 January 2026 after job seekers started asking its staff whether it was really hiring for something called the “Fireblocks Poker Platform.” Fireblocks found LinkedIn personas presenting as its executives, recruiters and hiring managers, professionally formatted PDFs named Fireblocks.pdf and Fireblocks-hiring.pdf, a detailed Figma board built to support the fiction, and a Google Meet interview run by someone calling himself an HR manager. The interviewer assigned a code review task, shared a repository link, and then left the call saying he had another meeting. Fireblocks lists twelve personas by name and role, and records that the campaign also used EtherHiding. It notes the recruiters used personal email addresses and Calendly links on personal domains rather than company ones.
Sekoia’s data shows how the impersonation is chosen. From 184 invitations pulled off the fake interview sites, Sekoia found 14 company names used as lures, and “Nine out of 14 provide centralised financial (CeFi) services”: Coinbase, KuCoin, Kraken, Circle, Securitize, BlockFi, Tether, Bybit and Robinhood. One, Archblock, is DeFi. Sekoia also found the job titles had shifted: “all the positions were not related to technical profiles in software development. They are mainly jobs of manager focusing on business development, asset management, product development or decentralised finance specialists.”
What happened on the video calls?
Two named firms examined fake video interviews in 2025 and reached opposite conclusions about the same technique. Both are printed here because the disagreement is the finding.
Huntress published on 18 June 2025, written by Alden Schmidt, Stuart Ashenbrenner and Jonathan Semon. The victim worked at a cryptocurrency foundation and got a Telegram message with a Calendly link that claimed to schedule a Google Meet, which redirected to a fake Zoom domain the attacker controlled. Weeks later, on a group call, the employee saw “deepfakes of known senior leadership within their company, along with external contacts.” Told their microphone was broken, the employee was sent a Telegram link to a “Zoom extension,” which was an AppleScript named zoom_sdk_support.scpt. What followed: a Nim binary called Telegram 2 that persisted as a LaunchDaemon, a Go backdoor called Root Troy V4, a C++ loader, an Objective-C keylogger called XScreen that captured keystrokes, clipboard and screen, and a Go infostealer called CryptoBot that hunted across 24 wallet extensions.
Kaspersky published on 28 October 2025, by Sojun Ryu and Omar Amin, on two campaigns it calls GhostCall and GhostHire, both attributed to BlueNoroff and tracked since April 2025. The fake Zoom page asks the target to enable their camera, then records them: “the JavaScript logic begins recording and sends a video chunk to the /upload endpoint of the actor’s fake Zoom domain every second.” The meeting screen shows three participants. Kaspersky’s finding on what those participants are: “Based on OSINT we were monitoring, many victims initially believed the videos they encountered were generated by deepfake or AI technology. However, our research revealed that these videos were, in fact, real recordings secretly taken from other victims who had been targeted by the same actor using the same method.” Kaspersky’s summary line is blunter: “The victim would join a fake call with genuine recordings of this threat’s other actual victims rather than deepfakes.”
Kaspersky did find generative AI elsewhere in the operation. Participant profile images were pulled from LinkedIn, Crunchbase or X and enhanced with GPT-4o, which Kaspersky identified from the C2PA provenance metadata OpenAI embeds in generated PNGs. Some of those image filenames carried the target’s own name. Kaspersky also flags comment lines in a stealer module, including one with a checkmark emoticon, as evidence that generative AI wrote parts of the malware.
Kaspersky’s victim data: macOS hosts infected by GhostCall in Japan, Italy, France, Singapore, Turkey, Spain, Sweden, India and Hong Kong since 2023, with GhostHire victims in Japan and Australia. From the operators’ own public storage server, “most victims were executives at tech companies and venture capital funds in the Web3/blockchain industry located in the APAC region, particularly in Singapore and Hong Kong.”
Kaspersky’s second campaign, GhostHire, is the recruiter version. The operator opens on Telegram with a link to a LinkedIn profile impersonating a senior recruiter at a US financial services firm, runs a short screening, then adds the target to a Telegram bot. The bot sends a ZIP file or a GitHub link “accompanied by a 30-minute time limit to complete the task, while putting pressure on the victim to quickly run the malicious project.”
Real-time face replacement in video interviews is documented, and it belongs to the other scheme. The FBI’s PSA I-012325-PSA of 23 January 2025, on DPRK IT workers, states: “North Korean IT workers have been observed using artificial intelligence and face-swapping technology during video job interviews to obfuscate their true identities.” ESET’s Virus Bulletin paper says the same of the IT workers, citing Unit 42: they “even perform faceswaps in real-time video interviews to look like the persona they are currently using.”
How big is this?
No agency or vendor has published a dollar figure for Contagious Interview. Google Threat Intelligence Group’s phrasing is as close as the public record gets: the campaign “has led to numerous cryptocurrency heists.” What exists is a set of partial counts from firms measuring different things.
| Measure | Figure | Source and date |
|---|---|---|
| Likely target IPs | 3,136 individual IP addresses, plus twenty potential victim organisations | Recorded Future Insikt Group, 21 January 2026, covering August 2024 to September 2025 |
| Victims observed | “hundreds of different victims around the world” across Windows, Linux and macOS | ESET, 20 February 2025 |
| Malicious npm packages | 338 packages, over 50,000 downloads, 180+ fake maintainer personas | Socket, 10 October 2025 |
| Further npm packages | 197 more packages, over 31,000 more downloads, 176 maintainer aliases | Socket, 26 November 2025 |
| Lure brands in use | 184 invitations across fake interview sites, using 14 company names | Sekoia, 31 March 2025 |
| DPRK crypto theft, all causes | $2.02 billion in 2025, up 51%, cumulative lower bound $6.75 billion | Chainalysis, 18 December 2025 |
Recorded Future’s twenty organisations sit across AI, cryptocurrency, financial services, IT services, marketing and software development, in Europe, South Asia, the Middle East and Central America. Its note on how individual compromise becomes corporate compromise: “In several cases, it is likely that job-seeking candidates executed malicious code on corporate devices, creating organizational exposure beyond the individual target.”
The Chainalysis line belongs in a different column from the rest. It covers all DPRK crypto theft, most of it from the Bybit exchange compromise, and none of it is broken out by campaign. Chainalysis does say the mechanism is shifting: North Korean actors are “often by embedding IT workers – one of DPRK’s principal attack vectors – inside crypto services to gain privileged access and enable high‑impact compromises.”
Who is behind it, and who says so?
Every vendor agrees on North Korea. They do not agree on where the cluster sits, and several say so directly.
| Firm | Name it uses | Position on Lazarus | Stated confidence |
|---|---|---|---|
| Unit 42 | Contagious Interview, CL-STA-0240 |
Notes others have made the link, declines to adopt it | Moderate confidence on DPRK (2023) |
| ESET | DeceptiveDevelopment | “we currently do not attribute to any known threat actor” | High confidence on DPRK alignment |
| Sekoia | ClickFake Interview | Attributes to Lazarus, and treats the campaign as continuous with Contagious Interview | High confidence on the continuity |
| Kaspersky | GhostCall, GhostHire | BlueNoroff, which it treats as distinct from Lazarus proper | Medium-high confidence |
| Cisco Talos | Famous Chollima | “a subgroup of Lazarus” | Not stated |
| Silent Push | Contagious Interview | “a subgroup of the North Korean state-sponsored APT group, Lazarus” | Not stated |
| Recorded Future | PurpleBravo | Distinguishes it from its own IT-worker designation, PurpleDelta | Not stated |
Unit 42’s caveat, written on 14 November 2024, is the sharpest statement of the problem: “Since our previous report on the two job-related campaigns, some researchers have begun attributing the Contagious Interview campaign to the well-known North Korean threat group, Lazarus. However, we are not certain whether the IT workers led the attacks or simply assisted other hacking groups. Despite this uncertainty, we continue to observe links between malware campaigns and North Korean IT workers, thus we track these activities under our temporary cluster names.”
ESET’s position is that the cluster is not one organisation at all. Its Virus Bulletin paper: “Unlike traditional threat actors, this group is not centralized, but rather consists of multiple small teams using shared codebases and knowledge to achieve similar objectives.” On skill: “The individuals behind all these activities are generally less skilled than one might expect from traditional APT actors like Lazarus, Andariel, or Kimsuky. Their malware is usually fairly simple, often containing bugs and code that doesn’t work as intended.”
Sekoia goes the other way. It attributes Contagious Interview to Lazarus, which it places under “the 3rd Department of the Reconnaissance General Bureau,” and it draws its own internal line: “Sekoia differentiates Lazarus from other sub-clusters of malicious activity like Bluenoroff, Andariel, and TEMP_Hermit.”
The naming is a mess by any measure. MITRE ATT&CK created a group entry for Contagious Interview, G1052, on 19 October 2025, last modified 12 May 2026, and lists six aliases: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo and TAG-121. That list omits UNC5342, CL-STA-0240, Famous Chollima, Void Dokkaebi and WaterPlum, all of which other vendors use for overlapping activity. lazarus.day, the running index of DPRK incident reporting, maps 27 related actor names to its Purple Bravo entry, each with a different vendor attached and a different first-seen date.
How is this different from the DPRK IT worker scheme?
These are two operations with two different objectives, and coverage merges them constantly.
| Contagious Interview | DPRK IT worker scheme | |
|---|---|---|
| The DPRK actor is | The employer | The employee |
| The victim is | A job seeker, and their employer if they used a work machine | A company that hires them |
| The objective | Run code on the target’s machine, take wallets and credentials | Draw a salary, and since 2024 also steal data and extort |
| Recorded Future name | PurpleBravo | PurpleDelta |
| US prosecutions | None | Four DPRK nationals indicted, plus multiple facilitator convictions |
| The defence | Endpoint policy and how candidates run assessment code | Hiring controls and identity verification |
The enforcement record makes the split concrete. On 30 June 2025 the Justice Department announced two indictments, an arrest, a plea agreement, “searches of 29 known or suspected ‘laptop farms’ across 16 states, and the seizure of 29 financial accounts used to launder illicit funds and 21 fraudulent websites.” The scheme it describes: North Korean individuals “fraudulently obtaining employment with U.S. companies as remote IT workers, using stolen and fake identities,” with help from people in the United States, China, the United Arab Emirates and Taiwan, reaching “more than 100 U.S. companies.”
One of those two indictments is the closest thing in the record to a crypto theft by this route. The Northern District of Georgia unsealed a five-count wire fraud and money laundering indictment charging four North Korean nationals, Kim Kwang Jin, Kang Tae Bok, Jong Pong Ju and Chang Nam Il. Prosecutors allege the four travelled to the United Arab Emirates on North Korean travel documents and worked as a co-located team; that Kim Kwang Jin was hired in December 2020 by an Atlanta blockchain research and development company using a stolen identity, and Jong Pong Ju in May 2021 by a Serbian virtual token company under the alias “Bryan Cho”; that in February 2022 Jong Pong Ju took roughly $175,000; and that in March 2022 Kim Kwang Jin took roughly $740,000 “by modifying the source code of two of his employer’s smart contracts, then sending it to a virtual currency address he controlled.” The indictment alleges both then mixed the proceeds through Tornado Cash. All four remain at large. These are allegations and the defendants are presumed innocent.
The Justice Department returned to the same programme on 14 November 2025 with five guilty pleas and two civil forfeiture complaints. Its description: “facilitators in the United States and Ukraine assisted North Korean actors with obtaining remote IT employment with U.S. companies. For example, the facilitators’ provided their own, false, or stolen identities, and hosted U.S. victim company-provided laptops at residences across the United States to create the false appearance that the IT workers were working domestically.” The totals: “these defendants’ fraudulent employment schemes impacted more than 136 U.S. victim companies, generated more than $2.2 million in revenue for the DPRK regime, and compromised the identities of more than 18 U.S. persons.”
The named defendants are Audricus Phagnasay, Jason Salazar and Alexander Paul Travis, who each pleaded guilty in the Southern District of Georgia to one count of wire fraud conspiracy; Oleksandr Didenko, a Ukrainian national who pleaded guilty in the District of Columbia on 10 November 2025 to wire fraud conspiracy and aggravated identity theft and agreed to forfeit more than $1.4 million; and Erick Ntekereze Prince, who pleaded guilty in the Southern District of Florida on 6 November 2025. Travis was an active-duty US Army soldier at the time and received at least $51,397. The two forfeiture complaints, 1:25-cv-03771 and 1:25-cv-03943, seek more than $15 million in USDT seized in March 2025 from APT38 actors, over four exchange heists in 2023. None of that touches Contagious Interview.
The two operations do connect at the edges, and three firms have documented it independently.
Unit 42 found the clearest instance on 14 November 2024. Tracking domains resolving to an IP tied to the fake MiroTalk campaign, it found the registrant was a DPRK IT worker cluster it tracks as CL-STA-0237, likely operating from Laos, which had used a US IT services company’s identity to apply for other jobs and which Unit 42 believes secured a position at a major tech company in 2022. Unit 42 called it “the second instance where we have observed connections between the Contagious Interview malware campaign and North Korean IT worker activities.”
ESET found it in GitHub metadata: “mutual follows between GitHub profiles where one side was associated with DeceptiveDevelopment, and the other contained fake CVs and other material related to North Korean IT worker activity.” Its assessment: “although these activities are conducted by two different groups, they are most likely connected and collaborating,” at medium confidence. And its framing of the limit: “The nature of the link between these two entities is unknown to us; we make a distinction between campaigns focused on distributing malware (DeceptiveDevelopment) and campaigns focused on gaining employment (North Korean IT workers).”
Recorded Future found it in infrastructure: “a likely PurpleBravo operator displaying activity consistent with North Korean IT worker behavior, IP addresses in Russia linked to North Korean IT workers communicating with PurpleBravo C2 servers, and administration traffic from the same Astrill VPN IP address associated with PurpleDelta activity.” Its conclusion is that the two are distinct designations with “meaningful intersections,” and that “some individuals may be active in both operations.”
What I think is going on
Several of the firms tracking this campaign describe the malware as mediocre, and having read their teardowns I think they are being generous. What makes the campaign work is the thing it asks you to do.
Think about what a technical interview looks like. A recruiter contacts you. You talk about the role. They send you a repository and ask you to fix a bug or add a feature, and they want it back by Friday. You clone it, you run npm install, you run the project to see the bug. At no point in that sequence does anything unusual happen. The attack is the normal thing. There is no attachment to be suspicious of, no login page to check the URL of, no payment to hesitate over. The entire chain of custody runs through actions you have taken a hundred times, on a machine you set up specifically to take them.
That is a harder problem than phishing and I do not think the industry has admitted it yet. Phishing training teaches you to look at the sender, hover the link, and slow down. None of that fires here. The sender is a person you have spoken to for a week. The link goes to GitHub. And you are not slowing down, because you are job hunting, which is a state that runs on urgency and hope. Kaspersky found the operators putting a 30-minute timer on the task through a Telegram bot. They know exactly what they are doing to you.
Now the deepfake question, because it is the most interesting disagreement in the record and almost nobody has noticed it.
In June 2025 Huntress reported an employee at a crypto foundation joining a Zoom call and seeing deepfaked versions of his own company’s senior leadership. In October 2025 Kaspersky examined what looks like the same technique and found the video feeds were not synthetic at all. They were real webcam recordings, harvested from earlier victims who had been asked to turn their cameras on for the “pre-join” screen, then replayed to the next target. Kaspersky went further and said victims themselves had assumed deepfakes.
Both firms are careful and both are describing DPRK operators running fake Zoom meetings against crypto staff in 2025. I do not think either is wrong. I think the operators do both, and that the difference matters more than a naming quibble, because it changes what you can detect. A deepfake has artefacts and can, in principle, be caught by a liveness check. A recording of a real person cannot, because it is a real person. And the recording pipeline means every victim who joined a fake call and enabled their camera became raw material for the next one. That is the part I keep coming back to. The scam manufactures its own props out of the people it catches.
The naming situation is a genuine operational problem and I would like someone to fix it. MITRE lists six aliases. lazarus.day maps 27. Unit 42 calls it CL-STA-0240, Google calls it UNC5342, Recorded Future calls it PurpleBravo, ESET calls it DeceptiveDevelopment, Talos and CrowdStrike call it Famous Chollima, Trend Micro calls it Void Dokkaebi, NTT calls it WaterPlum, DTEX calls it Gwisin Gang. If your security team gets an alert referencing one of those names and goes looking for context, there is a decent chance it finds three reports and concludes they are three campaigns. They are one campaign, or at least one loose federation of teams sharing a codebase, and the fragmentation is doing the operators a favour.
Then there is the number that does not exist. Nobody has published a loss figure for Contagious Interview. Not the FBI, not the DOJ, not Chainalysis, not any of the ten-plus firms tracking it. Google’s phrase is “numerous cryptocurrency heists.” I have looked for a figure and I cannot find one, and I want to be clear that I am telling you it is absent rather than guessing at it.
I think the absence is structural. This campaign steals from individuals, one at a time, in amounts nobody reports. A developer whose MetaMask gets drained for $40,000 does not file with IC3, does not appear in an exchange’s incident disclosure, and does not show up in the on-chain analytics that catch a bridge exploit, because there was no exploit. There was a valid signature from a compromised machine. So the campaign that every firm calls one of the most prolific DPRK operations running has, in public, a dollar value of zero. That gap is why it gets under-resourced relative to the bridge hacks, and I would bet the real number is uncomfortable.
The prosecution record has the same shape and the same cause. For the IT worker scheme: four North Korean nationals indicted in Georgia, five guilty pleas by facilitators in November 2025, 137 laptops carried out of houses across fourteen states in a single week in June 2025. For Contagious Interview: one seized domain. The government does not care less about the second one. The IT worker scheme is prosecutable in the United States because it needs Americans. Someone has to receive the laptop, plug it in, install the remote access software, and in one case show up for the drug test on the worker’s behalf. Those are domestic enablers with names and addresses. Contagious Interview needs a LinkedIn account, a GitHub repository and a VPS. The FBI took blocknovas.com, and the operators registered more.
On the two schemes being conflated, I want to be unfair to the coverage for a moment, because the conflation has a real cost. If you read “North Korean fake job scam” and file it mentally under hiring risk, you will send your HR team on identity-verification training and do nothing about the developer who runs candidate repositories on the laptop that holds the multisig signing key. Those are opposite defences for opposite attacks. One is about who you let in. The other is about what your own people run. A firm can be excellent at the first and wide open to the second, and most are.
The last thing I would flag is where the targeting went. Sekoia’s data from March 2025 found that across 184 fake interview invitations, the roles being advertised were mostly business development, asset management and product management, and the companies being impersonated were mostly centralised exchanges. That is a deliberate move away from developers. The operators worked out that a business development manager at an exchange also has a laptop, also has a browser wallet, and is far less likely to look at a package’s source before running it.
Two things I will not claim. I will not say any named individual did this, because nobody has been charged over this campaign and the persona names in the research (Mehmet Demir, Onder Kayabasi, the twelve Fireblocks impersonations) are fabrications built partly from stolen photographs of real people who are themselves victims. Silent Push removed material from its own report after a real person said their identity had been taken. And I will not treat the Lazarus attribution as settled, because ESET, the firm with the deepest look at the malware, explicitly declines to make it.
What reduces your exposure
No custody arrangement helps here. No entity structure helps here. The attack goes at the machine your keys are on and at the credentials sitting in your browser, and the legal wrapper around the assets never enters into it. A trust that owns a wallet is as exposed as a person who owns one. Anyone selling you a structure as an answer to this is selling you something else.
What lowers the risk is a change in how you run other people’s code, and a change in how your firm runs hiring. None of it removes the risk.
If you work in this industry
Never run unfamiliar code on the machine that holds your keys. This is the whole article in one sentence. A disposable virtual machine, a spare laptop, or a device the tester provides. The FBI says the same thing in its own advisory and it is worth reading in its own words: “Avoid taking pre-employment tests or executing code on company owned laptops or devices. If a pre-employment test requires code execution, insist on using a virtual machine on a non-company connected device, or on a device provided by the tester.”
Treat “run this to see the bug” as hostile until proven otherwise. So is “run this to fix your camera,” “install our conferencing app,” and any error message that hands you a command to paste. Sekoia’s whole ClickFake chain runs on a fake camera error. Kaspersky’s runs on a fake audio problem. The error is the attack.
Verify the recruiter through a channel they did not choose. Go to the company’s own careers page and check the role exists. Message someone at the company you already know. Fireblocks found the campaign against it because candidates asked Fireblocks employees whether the job was real, which is exactly the right instinct, and it is also how the campaign got shut down.
Assume browser wallet extensions on a machine that runs candidate code are already gone. BeaverTail copies the extension databases before you notice anything. If you have run something you should not have, move funds from any hot wallet on that machine first and rotate credentials second, on a different device.
Watch for the specific signals the research keeps finding. A recruiter using a personal email address instead of a company domain. A Calendly link on a personal domain. A LinkedIn profile with an AI-written summary and almost no history before it contacted you. An interviewer who assigns the coding task and then leaves the call immediately. A private repository you have to hand over an email address to access. A time limit on a take-home task. Fireblocks published its own version of this list after being impersonated, and every item on it came from a real approach.
One more, from the same Fireblocks report and easy to miss: interviewers asking about your cryptocurrency payment preferences. No legitimate hiring process needs to know that at interview stage. It is reconnaissance.
If you run a firm
Give candidates an environment. A non-persistent VM, a cloud sandbox, a locked-down loaner. Microsoft’s guidance from March 2026 says it plainly: “Use a dedicated, isolated environment for coding tests and take-home assignments (for example, a non-persistent virtual machine). Do not use a primary corporate workstation that has access to production credentials, internal repositories, or privileged cloud sessions.” This applies to your own hiring, and it applies with more force to your staff being interviewed elsewhere, which you cannot control and should assume is happening.
Write the policy for recruiter-provided repositories, because right now your developers do not have one. Microsoft again: “Establish a policy that requires review of any recruiter-provided repository before running scripts, installing dependencies, or executing tasks. Treat ‘paste-and-run’ commands and ‘quick fix’ instructions as high-risk.”
Restrict where developer runtimes can execute. Node, Python and PowerShell launching from Downloads or a temp folder is the shape of this entire campaign. Microsoft’s detection guidance points at the same chain: a code editor spawning a shell, spawning curl or wget, spawning a script. Application control that blocks execution from those directories costs a developer very little and breaks the delivery step.
Separate signing from everything else. Whatever machine approves transfers should not be a machine anyone browses, hires, or runs assessments on. This is not exotic advice and it remains the single largest gap between firms that get hurt by this and firms that do not.
Fix the secrets first, since that is what the second stage actually goes for. InvisibleFerret sweeps .env files across whole drives, and OtterCookie searches recursively for keys inside documents and images. Short-lived credentials in a vault, MFA on source control and cloud consoles, and no long-lived tokens sitting in local config files.
And run the other-direction control too, because it is a separate problem with a separate answer. Verify who you are hiring. The FBI’s January 2025 PSA lists the measures: cross-check resumes for duplicate content and contact details, watch for reused VoIP numbers across supposedly different applicants, verify third-party staffing firms, and complete as much of hiring and onboarding in person as you can. That advice does nothing against Contagious Interview, and the endpoint policy above does nothing against a DPRK IT worker on your payroll. You need both, and you should be able to say which control is for which.
The test for including one is whether a structure would have changed the outcome, and this is a targeting problem.
Sources
- FBI Internet Crime Complaint Center, Public Service Announcement I-090324-PSA, “North Korea Aggressively Targeting Crypto Industry with Well-Disguised Social Engineering Attacks”, 3 September 2024.
https://www.ic3.gov/psa/2024/psa240903 - FBI Internet Crime Complaint Center, Public Service Announcement I-012325-PSA, “North Korean IT Workers Conducting Data Extortion”, 23 January 2025.
https://www.ic3.gov/PSA/2025/PSA250123 - US Department of Justice, Office of Public Affairs, “Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers’ Illicit Revenue Generation Schemes”, 30 June 2025. Includes the Northern District of Georgia indictment of Kim Kwang Jin, Kang Tae Bok, Jong Pong Ju and Chang Nam Il.
https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote - US Department of Justice, Office of Public Affairs, “Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation”, 14 November 2025.
https://www.justice.gov/opa/pr/justice-department-announces-nationwide-actions-combat-illicit-north-korean-government - FBI domain seizure notice served at
https://blocknovas.com/, read 1 August 2026. Seizure warrant issued by the US District Court for the Northern District of Texas. - Palo Alto Networks Unit 42, “Hacking Employers and Seeking Employment: Two Job-Related Campaigns Bear Hallmarks of North Korean Threat Actors”, 21 November 2023.
https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/ - Palo Alto Networks Unit 42, “Contagious Interview: DPRK Threat Actors Lure Tech Industry Job Seekers to Install New Variants of BeaverTail and InvisibleFerret Malware”, 9 October 2024.
https://unit42.paloaltonetworks.com/north-korean-threat-actors-lure-tech-job-seekers-as-fake-recruiters/ - Palo Alto Networks Unit 42, “Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack”, 14 November 2024.
https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/ - ESET Research, “DeceptiveDevelopment targets freelance developers”, Matěj Havránek, 20 February 2025.
https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/ - Matěj Havránek and Peter Kálnai, ESET, “DeceptiveDevelopment: from primitive crypto theft to sophisticated AI-based deception”, Virus Bulletin conference paper, Berlin, 24 to 26 September 2025, 18 pages.
- NTT Security Japan, “OtterCookie, new malware used in Contagious Interview campaign”, Masaya Motoda, Rintaro Koike and Ryu Hiyoshi, English version published 16 January 2025.
https://jp.security.ntt/tech_blog/en-contagious-interview-ottercookie - Sekoia Threat Detection and Research, “ClickFake Interview campaign by Lazarus”, 31 March 2025.
https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/ - Google Threat Intelligence Group, “DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains”, Blas Kojusner, Robert Wallace and Joseph Dobson, 16 October 2025.
https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding - Cisco Talos, “BeaverTail and OtterCookie evolve with a new Javascript module”, Vanja Svajcer and Michael Kelley, 16 October 2025.
https://blog.talosintelligence.com/beavertail-and-ottercookie/ - Kaspersky GReAT, “BlueNoroff’s latest campaigns: GhostCall and GhostHire”, Sojun Ryu and Omar Amin, 28 October 2025.
https://securelist.com/bluenoroff-apt-campaigns-ghostcall-ghosthire/117842/ - Huntress, “Inside the BlueNoroff Web3 macOS Intrusion Analysis”, Alden Schmidt, Stuart Ashenbrenner and Jonathan Semon, 18 June 2025.
https://www.huntress.com/blog/inside-bluenoroff-web3-intrusion-analysis - Silent Push, “Contagious Interview front company scam”, 24 April 2025.
https://www.silentpush.com/blog/contagious-interview-front-companies/ - Recorded Future, Insikt Group, “PurpleBravo’s Targeting of the IT Software Supply Chain”, 21 January 2026.
https://www.recordedfuture.com/research/purplebravos-targeting-it-software-supply-chain - Socket, “North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages”, Kirill Boychenko, 10 October 2025.
https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages - Socket, “Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacks”, Kirill Boychenko, 26 November 2025.
https://socket.dev/blog/north-korea-contagious-interview-npm-attacks - Microsoft Defender Experts and Microsoft Defender Security Research Team, “Contagious Interview: Malware delivered through fake developer job interviews”, 11 March 2026.
https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/ - Fireblocks, “Disrupting a Recruiting Impersonation Scam: Anatomy of Operation Contagious Interview”, Ori Hershko, 22 January 2026.
https://www.fireblocks.com/blog/contagious-interview-recruiting-scam - Chainalysis, 2026 Crypto Crime Report stolen-funds chapter, published 18 December 2025 and last modified 11 June 2026. The page carries two titles: “2025 Crypto Theft Reaches $3.4 Billion” in its metadata and “North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion” on the page.
https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/ - MITRE ATT&CK, group
G1052, Contagious Interview, created 19 October 2025, last modified 12 May 2026.https://attack.mitre.org/groups/G1052/ lazarus.day, Purple Bravo actor page and related-actor index, read 1 August 2026.https://lazarus.day/actors/alias/purplebravo
Disclosure. Max Avery is affiliated with Digital Ascension Group (DAG). Investment advisory services are offered through DAG Wealth, an SEC-registered investment adviser (CRD No. 328627). Registration does not imply a certain level of skill or training. DAG is not a law firm and does not provide legal or tax advice. Custody arrangements with third-party independent qualified custodians reduce certain risks but do not eliminate them. Nothing here is investment, legal, or tax advice, or a recommendation to buy or sell any asset. This article describes matters of public record; charges are allegations and defendants are presumed innocent unless and until proven guilty.