Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft

North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft

Posted on September 21, 2026 By CWS

In an alarming development, North Korean cybercriminals orchestrated a campaign known as ‘Contagious Interview,’ compromising over 30,000 devices in more than 100 countries. This operation has resulted in the theft of over $10.71 million in cryptocurrency from 7,000 digital wallets, according to a recent cybersecurity advisory.

Targeting Tech Professionals

The campaign primarily affects web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. These threat actors, identified under various aliases such as CL-STA-0240, DeceptiveDevelopment, and others, have targeted individuals globally, posing as recruiters on platforms like LinkedIn to initiate contact.

Victims are persuaded to undertake a job assessment or coding test, which triggers a series of malware deployments. The malicious software used includes names like BeaverTail and InvisibleFerret, designed to establish backdoor access for sustained data exfiltration and control.

International Response and Analysis

Security agencies from Japan, the U.S., Australia, and Germany have issued alerts about these activities. The campaign is believed to be linked to North Korean IT workers operating under the 313 General Bureau, as per assessments from cybersecurity firms such as DTEX.

WaterPlum, another North Korean group, has been detected utilizing online chat platforms to interact with developers in the U.S. and Japan. They have been employing intermediaries to manage laptop farms, facilitating remote management of compromised devices.

Broader Implications and Future Outlook

This campaign highlights North Korea’s escalating use of technology and AI to conduct cyber operations for financial gain. The infamous IT worker scheme is part of a broader strategy to infiltrate Western companies by using fabricated identities to evade sanctions and legal restrictions.

Recent analyses from Kudelski Security and Silent Push reveal that North Korean operatives are recruiting proxies through platforms like Discord, offering significant financial incentives. These proxies serve as the public face of operations, bypassing regional hiring constraints and compliance checks.

The ongoing threat underscores the need for heightened cybersecurity awareness and international cooperation to counteract such sophisticated cyber-espionage activities. As North Korea continues to refine its tactics, organizations worldwide must remain vigilant and proactive in safeguarding their digital assets.

The Hacker News Tags:AI, Blockchain, Contagious Interview, crypto wallets, cryptocurrency theft, cyber threat, Cybersecurity, Hacking, IT security, job scams, Malware, North Korea, Remote Access Trojans, VPN services, WaterPlum

Post navigation

Previous Post: Google Faces €403 Million Fine for GDPR Breach on Location Data
Next Post: AWS Swiftly Quarantines Exposed IAM Keys on GitHub

Related Posts

FBI Takes Down Chinese Hacking Platforms Targeting U.S. FBI Takes Down Chinese Hacking Platforms Targeting U.S. The Hacker News
Weekly Cybersecurity Recap: Major Threats and Developments Weekly Cybersecurity Recap: Major Threats and Developments The Hacker News
OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls The Hacker News
AI Arms Race: Prioritizing Unified Exposure Management AI Arms Race: Prioritizing Unified Exposure Management The Hacker News
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App The Hacker News
Critical Vulnerability in Anthropic’s MCP Exposes Developer Machines to Remote Exploits Critical Vulnerability in Anthropic’s MCP Exposes Developer Machines to Remote Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub
  • North Korean Cyber Campaign Targets 30,000 Devices for Crypto Theft
  • Google Faces €403 Million Fine for GDPR Breach on Location Data
  • Fake LastPass Installer Uses Signed Driver to Bypass Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark