North Korea-Linked Group Steals $10.71M in Crypto from 30,000 Compromised Devices
A global cyber threat group, suspected to be linked to North Korea's government, has compromised at least 30,000 devices in over 100 countries and stolen $10.71 million worth of cryptocurrency from victims.
The Contagious Interview campaign targets individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies, with the threat actors infiltrating unsuspecting job seekers' computer networks to harvest sensitive information and steal cryptocurrency.
According to a joint cybersecurity advisory from agencies in Japan, the U.S., Australia, and Germany, the campaign has been ongoing since at least 2022, using social media platforms like LinkedIn to pose as prospective employers and recruiters.
BeaverTail, InvisibleFerret, and other malware families have been deployed in the infection chain, providing backdoor access for remote device management and data exfiltration. The threat actors also use online chat platforms to communicate with developers and employ enablers in various countries to set up laptop farms for remote device management.