Home/Guides/Threats & Attacks
Threats & AttacksBeginner7 min read · August 6, 20261,550 words

The 'Contagious Interview' Scam: How North Korean Hackers Use Fake Job Offers to Breach Small Businesses

B

BizShield Editorial Team

Updated August 6, 2026

Quick Answer

"Contagious Interview" is an ongoing campaign, tracked by Microsoft since 2022, in which North Korea-linked hackers pose as recruiters and lure software developers and contractors into a fake technical interview. Victims are asked to download and run a "coding test" that secretly installs malware, stealing credentials, source code, and cryptocurrency wallets. Security researcher Vangelis Stykas spent 22 months inside the operators' own infrastructure and, presenting at Black Hat Las Vegas in 2026, revealed 1,640 compromised companies across 57 countries, with 700–800 suffering severe intrusions including root-level server and cloud access. Named victims included Boston Children's Hospital, Oppo, and AEON Smart Technology. Small businesses that hire remote developers or contractors are directly in this campaign's target zone.

Affiliate disclosure:Some links below may earn us a commission at no extra cost to you. We only recommend tools we've tested and trust.

Trains Teams to Spot Social Engineering

KnowBe4 Security Training

Try KnowBe4 Free →
The 'Contagious Interview' Scam: How North Korean Hackers Use Fake Job Offers to Breach Small Businesses

A security researcher spent 22 months inside North Korean hacking infrastructure and found 1,640 compromised companies across 57 countries — many breached through a single fake coding interview.

A Researcher Spent 22 Months Inside North Korea's Hacking Operation

Vangelis Stykas, a Greece-based security researcher and CTO of cybersecurity firm Kumio, spent roughly 22 months with access to the command-and-control infrastructure used by North Korea-linked hackers — access he gained partly because the operators infected their own workstations with their own malware, exposing their internal Slack and Discord communications and around 5 terabytes of stolen data to him in the process.

Presenting his findings at Black Hat Las Vegas in 2026, Stykas revealed that the operation had compromised 1,640 companies across 57 countries, with 700 to 800 of those suffering severe intrusions — root-level access to servers, AWS cloud environments, and cryptocurrency wallets. Disclosed victims included Boston Children's Hospital (whose exposure included a COVID-19 health database), Chinese phone manufacturer Oppo, and Japanese tech firm AEON Smart Technology. This is one of the largest documented views into a nation-state hacking operation's actual victim list, not just its known techniques.

How the "Contagious Interview" Scam Actually Works

How the "Contagious Interview" Scam Actually Works

The primary technique behind this scale of compromise is a campaign security researchers call "Contagious Interview," which Microsoft has tracked since as early as 2022. It doesn't rely on a technical exploit at all — it relies on the hiring process itself.

The pattern is consistent: attackers pose as recruiters or hiring managers, often reaching out unsolicited on LinkedIn or in developer communities, and run what looks like a completely normal technical interview process for a legitimate-sounding remote role. At some point, the candidate is asked to complete a "coding challenge" or technical assessment — which requires downloading and running a project from a link the fake recruiter provides. That project contains hidden malware. Once run, it can steal saved credentials, browser session data, cryptocurrency wallet keys, and source code from the victim's machine, and in many cases gives the attacker a persistent foothold for further access.

Why This Is a Small Business Problem, Not Just a Big Tech Problem

It's tempting to read this as a story about crypto exchanges and Silicon Valley — but the target profile is exactly the hiring pattern most small businesses now use. Hiring a remote developer, designer, or technical contractor through a freelance platform or LinkedIn outreach, without ever meeting them in person, is completely normal in 2026 — and it's precisely the setup Contagious Interview is built to exploit.

The named victim list makes the point directly: a children's hospital and a consumer electronics company aren't crypto-native businesses, they're ordinary organizations that hired the wrong "candidate" or had an employee's device compromised through this pipeline. If your business works with remote contractors, freelance developers, or anyone brought on through a fast-moving hiring process, you have the exact exposure this campaign targets — regardless of your industry or size.

Red Flags During Interviews and Contractor Onboarding

Red Flags During Interviews and Contractor Onboarding

Most Contagious Interview compromises share a recognizable pattern once you know what to look for.

  • An unsolicited recruiter contact via LinkedIn, Telegram, or Discord for a role the candidate never applied to.
  • A "coding test" or technical assessment that requires downloading and running an executable, script, or unfamiliar package — outside of a browser-based or sandboxed testing environment.
  • Pressure to complete the test quickly, discouraging the candidate from reviewing the code first.
  • Any request to disable antivirus, run the test with elevated/admin permissions, or use a personal device with access to other accounts.
  • A hiring process that moves unusually fast with little verification of the company's identity.

What to Do — Whether You're Hiring or Being Interviewed

If you're hiring: verify a recruiter or company's identity independently before any technical exercise, require any take-home test to run inside an isolated virtual machine with no access to real credentials, and apply least-privilege access by default for new contractors — don't hand out repository or system access until identity and work product are verified.

If you're the one being interviewed: never run unreviewed code on a machine that has access to production systems, cloud credentials, or a cryptocurrency wallet. Use a disposable VM or sandbox for any take-home assessment, no exceptions. If something about a technical test asks you to disable security software or run it with elevated permissions, that's not a coding challenge — treat it as a compromise attempt and stop.

The underlying lesson from Stykas's research applies well beyond this one campaign: attackers follow whatever process is most convenient to exploit, and for many businesses today, that process is hiring. Building basic verification into how you bring on contractors costs almost nothing and closes one of the more creative attack paths currently in active use.

Frequently Asked Questions

What is the "Contagious Interview" campaign?

It's a social engineering campaign, tracked by Microsoft since 2022 and linked to North Korean state-backed hackers, that targets software developers and contractors. Attackers pose as recruiters, run a fake hiring process, and ask the candidate to complete a "coding challenge" that requires downloading and running a project — which secretly installs malware. It has since been documented compromising well over a thousand organizations worldwide.

Does this only affect crypto and tech companies?

No. While cryptocurrency wallet theft is a major goal, disclosed victims include a hospital, a consumer electronics manufacturer, and a wide range of ordinary businesses across 57 countries. Any organization that hires remote developers, designers, or technical contractors — which today includes most small businesses — is a plausible target, not just crypto-native firms.

What are the red flags during a technical interview or contractor onboarding?

Be cautious of: an unsolicited recruiter contact via LinkedIn, Telegram, or Discord for a role you didn't apply to; a "coding test" that requires downloading and running an executable or unfamiliar package outside a sandboxed environment; pressure to complete the test quickly; and any request to disable antivirus or run code with elevated permissions "so the test works." Legitimate technical interviews don't require any of this.

What should I do if I already ran a suspicious coding test?

Disconnect the device from the network immediately, change any passwords or API keys that were accessible from that machine (especially cloud, source control, and cryptocurrency accounts), and run a full scan with reputable endpoint protection. If the device had any access to employer or client systems, report it to IT/security immediately — the earlier a compromised device is reported, the smaller the blast radius.

Contagious InterviewNorth Korea hackersfake job scamhiring securityremote contractor risksocial engineering