# North Korean cyber recruitment fraud

> Live situation record from CLSTR: https://clstr.news/situations/north-korean-cyber-recruitment-fraud
> Updated: 2026-09-18T06:00:00.000Z. Sources: 19. Developments: 2.

North Korean cyber operatives are utilizing fraudulent recruitment tactics to infiltrate foreign companies and bypass international sanctions. Initial reports indicate a sophisticated method where North Korean teams use third-country nationals from nations including Iran, South Africa, Nigeria, Lebanon, and India to act as proxy interviewers. These facilitators participate in video interviews and coding tests to evade detection, such as AI deepfake filters, before handing technical work to North Korean operatives. A US-led assessment estimated these disguised IT employment schemes earned North Korea up to $800 million in 2024, funds believed to finance weapons development.

Following these developments, intelligence agencies in Germany, Japan, the United States, and Australia issued a joint warning regarding a specific campaign dubbed ‘Contagious Interview’. This campaign, attributed to the ‘Waterplum’ group, involves state-sponsored actors using social engineering on social media and freelance marketplaces. By posing as representatives from AI or cryptocurrency firms, attackers guide candidates to download malicious files during fraudulent interviews. These files facilitate the theft of sensitive data and cryptocurrency, which is reportedly used to fund North Korea’s sanctioned programs.

Recent data indicates the scale of the ‘Contagious Interview’ operation has expanded significantly, with reports suggesting the group has targeted more than 30,000 devices across more than 100 countries. In at least one documented instance, hackers successfully stole 11 million dollars in cryptocurrency. These stolen assets are believed to be used to bypass international sanctions and finance North Korea’s ballistic missile and weapons programs.

## Claims

- A North Korean cyber group is targeting IT specialists to steal cryptocurrency. (corroborated by 12 sources)
- The stolen cryptocurrency is intended to bypass sanctions and fund North Korea's weapons program. (corroborated by 12 sources)
- The cyber campaign is referred to as ‘Contagious Interview’ within the IT security community. (corroborated by 11 sources)
- Attackers use social media, job platforms, and freelance marketplaces to contact software developers. (corroborated by 11 sources)
- The cybercriminals pose as representatives of AI or cryptocurrency companies during the recruitment process. (corroborated by 11 sources)
- The attack involves candidates downloading a file for a job task that contains malware. (corroborated by 11 sources)
- North Korean hackers stole at least 11 million dollars in cryptocurrency from IT professionals across more than 100 countries. (single source)
- The cyberattack targeted more than 30,000 devices used by IT engineers. (single source)

## Timeline

### 2026-09-18: North Korea cyber group targets IT specialists via fake job offers

Security agencies warn of a North Korean cyber campaign, ‘Contagious Interview,’ targeting IT specialists via fake job offers to steal cryptocurrency and fund weapons programs.

13 sources. https://clstr.news/cluster/north-korea-cyber-group-targets-it-specialists-via-fake-job-interviews

### 2026-09-12: North Korea uses third-country proxies to bypass IT job interviews

North Korea is using IT workers from third countries like Iran and Nigeria to act as proxies in job interviews to infiltrate Western companies and fund weapons programs.

6 sources. https://clstr.news/cluster/north-korea-uses-third-country-proxies-to-bypass-western-it-hiring

---
Cite as: North Korean cyber recruitment fraud. CLSTR, https://clstr.news/situations/north-korean-cyber-recruitment-fraud
