A joint report by cybersecurity experts from Japan, the United States, Germany, and Australia has uncovered a long-running cyber campaign attributed to North Korean hackers. This operation, known as "Contagious Interview" or Operation DreamJob, has infected over 30,000 devices across 100 countries and stolen cryptocurrency from about 7,000 individuals, resulting in more than $10 million being transferred to the North Korean government. The campaign has been active for nearly four years and is believed to be state-sponsored, though definitive proof remains difficult to obtain. Experts suggest that the hacking group behind the campaign is likely the Lazarus Group, a well-known North Korean cyber unit. However, some researchers believe other groups, such as DeceptiveDevelopment, Gwisin Gang, and others, may also be involved. These groups are known for conducting complex cyber operations, often targeting financial institutions and technology firms. North Korean hackers create fake profiles on social media platforms like LinkedIn, using real data stolen from past breaches and AI-generated content to make the profiles appear legitimate. These fake personas apply for jobs across various industries, often targeting roles in web design, engineering, and blockchain technologies. Once hired, the hackers use their access to install malware, steal login credentials, and extract sensitive information, including cryptocurrency. To avoid detection, the hackers operate from "laptop farms" in countries with more lenient cyber regulations, such as China. These remote setups allow them to access target networks without revealing their true location. Additionally, they create fake companies and job postings to lure candidates into downloading malicious software during the hiring process. Once inside a network, they often pivot to the target’s employer to carry out similar attacks. To protect against such threats, security agencies recommend that companies verify the IP addresses of job applicants to ensure they match the claimed location, check contact details, and be wary of an unusually high number of applications for rare positions. They also advise asking detailed questions about the applicant's background and being cautious if inconsistencies arise. Since North Korean hackers often prefer cryptocurrency payments, businesses are encouraged to verify payment requests and be alert to unusual requests, such as sending money to an account under someone else's name.