Here’s the thing about job interviews: they’re already stressful enough without the possibility that your coding test is actually North Korean malware. Yet that’s exactly what’s been happening to software developers worldwide since at least 2022, and the scale is far worse than anyone previously understood.
Vangelis Stykas, CTO of security firm Kumio, revealed at Black Hat Las Vegas in August 2026 that he spent over 22 months with persistent access to multiple North Korean command-and-control servers. What he found during that time paints a grim picture: approximately 1,640 organizations across 57 countries were compromised through a campaign known as “Contagious Interview.”
The scope of the breach
The attack methodology was deceptively simple. North Korean operatives posed as recruiters or hiring managers, luring software developers into fake job interviews. The candidates were then asked to complete coding tests, which served as delivery vehicles for malware.
Of the 1,640 compromised organizations, between 700 and 800 experienced what Stykas described as severe intrusions. We’re talking root access and AWS access, the kind of permissions that essentially hand over the keys to an organization’s entire digital infrastructure.
The attackers went straight for cryptocurrency wallets, private keys, and blockchain infrastructure. Other sensitive data was largely ignored, which tells you everything about the financial motivation driving Pyongyang’s cyber operations.
Stykas publicly named a dozen affected organizations, including Coinbase, Uniswap Labs, AEON Smart Technology, Italy’s Supreme Judicial Council, Boston Children’s Hospital, and Belgium’s Flemish government digital arm, Digitaal Vlaanderen.
Inside the hackers’ own systems
By maintaining access to the attackers’ own command-and-control infrastructure for nearly two years, Stykas accumulated roughly 5 terabytes of hacker-related data.
That trove included the attackers’ own communication channels on Slack and Discord, revealing operational lapses in the hackers’ own practices.
Some compromised contractors provided the attackers with access to as many as 30 firms during the exploitation process. In other words, one successful social engineering attack on a single freelance developer could cascade into dozens of corporate breaches.
Who responded, and who didn’t
Stykas disclosed his findings to affected organizations, and the responses varied dramatically. Authorities in Belgium and Japan confirmed concrete remediation efforts following the disclosures. Others, according to the research, “did not engage substantively with the findings.”
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
11









English (US) ·