
Stykas said fake coding tests used in the "Contagious Interview" campaign delivered malware that exposed root and AWS access, private keys and cloud credentials, with attackers prioritizing wallets and other blockchain infrastructure.
North Korean operatives posing as recruiters used fake job interviews and coding tests to compromise about 1,640 organizations across 57 countries in a campaign dubbed "Contagious Interview," with Vangelis Stykas saying at Black Hat Las Vegas in August 2026 that he spent 22 months inside multiple command-and-control servers and collected about 5 terabytes of attacker data. He said 700 to 800 victims suffered severe breaches that gave the crews server root access, AWS root permissions or cryptocurrency wallet keys, and that contractors sometimes carried live credentials for as many as 30 companies. Palo Alto Networks first named the tactic in November 2023, while Microsoft said in March 2026 that fake code packages on GitHub, GitLab and Bitbucket could trigger malicious code execution through a Visual Studio Code trust prompt; the attackers then hunted API tokens, cloud credentials, signing keys, private keys, crypto wallets and password manager files. Stykas said the crews prioritized wallets and blockchain access over other reachable records, warned organizations including Coinbase and Uniswap Labs, and traced one Boston Children's Hospital exposure to a former contractor's personal device, a characterization the hospital disputed after saying it revoked credentials within hours and found no evidence its systems were accessed. The findings add to a broader picture of DPRK-linked crypto theft, which CrowdStrike said reached $2.02 billion in 2025, up 51% from a year earlier, while TRM Labs said April's $285 million Drift Protocol theft involved in-person contact and that Pyongyang-linked thefts have exceeded $6 billion since 2017.