North Korean 'Contagious Interview' Campaign Breaches 30,000 Devices in 100 Countries, Joint Report Says
A joint report from law enforcement agencies in Japan, the US, Germany and Australia says North Korean operatives behind the 'Contagious Interview' hacking campaign have compromised over 30,000 devices in 100 countries and stolen more than $10 million in cryptocurrency from about 7,000 people.
The campaign, also known as Operation DreamJob, has been running for almost four years. The cybersecurity community generally attributes it to the North Korean government, although more precise attribution is difficult. Some researchers believe it is the work of the Lazarus Group, one of the largest state-sponsored actors; others believe several groups are involved, tracked under names including DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo and TAG-121.
According to the report, as reported by TechRadar, the operatives exploit shortages of skilled workers in the West to get inside organizations, steal sensitive data and ultimately money. They build entire fake personas on social media platforms such as LinkedIn and apply to hundreds, sometimes thousands, of job advertisements in IT, healthcare and other industries. The personas combine legitimate information taken in data breaches, including names, Social Security numbers and addresses, with AI-generated images, video and audio. Once hired, the operatives use their access to infect employers with malware, steal login credentials and other access, and exfiltrate sensitive files and cryptocurrency.
The scheme also runs in the opposite direction. The attackers create fake companies and fake job openings, then approach targets with offers of lucrative positions on appealing projects. As part of the hiring process, candidates are asked to download and work on code that is in fact malicious. The North Koreans then pivot to the candidates' current employers, with the same result.
To defeat corporate checks on the IP address and location employees log in from, the attackers have set up "laptop farms" abroad, usually in countries with looser restrictions that remain friendly to North Korea, such as China, hosting hundreds of laptops. Traffic is routed through those machines so the operatives' real location is not revealed. Individual web designers, engineers and specialists in cryptocurrency, blockchain and Web3 technologies are the primary targets, the report says, and businesses should be suspicious when a position that normally draws few applicants suddenly receives numerous applications in a short time.
"If possible, verify that IP addresses generally match the applicant's claimed residence," the report states. "Carefully check all contact information. Calling an applicant's phone number may reveal the number is out of service." The agencies also warned that a job application is often a group effort: "Even if a single individual appears to be applying, multiple people may be collaborating behind the scenes, inflating the perceived skill set." Employers are advised to confirm certifications by checking registration numbers and to request detailed explanations when inconsistencies appear. Asking applicants about their hometown, local weather or hobbies can also expose a scammer.
North Korean IT workers tend to prefer payment in cryptocurrency and may ask for remuneration to be sent to an account held in someone else's name, according to the report. Contagious Interview has evolved considerably over its roughly four years of operation, and the security agencies warn that changes to the standard playbook can occur at any time and that variations should be expected.
Editor's Summary
The joint report from Japan, the United States, Germany and Australia attributes a four-year campaign of fake job recruitment to North Korean operatives, who used fabricated personas, bogus companies and overseas laptop farms to breach more than 30,000 devices in 100 countries. The agencies say the operation netted over $10 million in cryptocurrency from about 7,000 victims, and they urge employers to verify applicants' IP addresses, contact details and credentials, and to treat cryptocurrency payment requests as a warning sign.