Threat intelligence analysis indicates that a North Korean–linked cyber campaign tracked as PurpleBravo targeted at least 3,136 unique IP addresses pretending to conduct job interviews – a scheme known as “Contagious Interview.”

Who Was Affected

The hackers went after about 20 companies in different industries, including artificial intelligence, cryptocurrency, financial services, IT and software companies, and marketing firms. These targeted organizations are located in countries across Europe, South Asia, the Middle East, and Central America.

How the Attack Worked

The hackers have been running this operation since late 2023. Between August 2024 and September 2025, they focused mainly on targets in South Asia and North America. The attacks reached companies in Belgium, Bulgaria, Costa Rica, India, Italy, the Netherlands, Pakistan, Romania, the United Arab Emirates, and Vietnam.

The scheme worked like this: hackers posed as job recruiters or fellow developers and invited people to complete coding tests as part of fake job interviews. When job seekers ran these “tests” on their work computers, they unknowingly installed malicious software. This turned what looked like an attack on one person into a breach of their entire company’s network.

The Hackers’ Tools and Tricks

The attackers used several clever tactics. They created fake profiles on LinkedIn, pretending to be developers or recruiters from Odesa, Ukraine. They set up malicious projects on GitHub (a popular code-sharing website) that contained hidden malware. They abused Microsoft Visual Studio Code, a widely trusted programming tool that developers use every day. They also distributed two main types of malicious software: BeaverTail (which steals information) and GolangGhost (which creates a backdoor into systems).

The hackers controlled their operation through servers spread across 17 different hosting companies and used Astrill VPN software to hide their activities. Their management activity traced back to IP addresses in China, which is consistent with how North Korean hackers have operated in the past.

Connection to Broader North Korean Operations

This campaign is linked to another North Korean effort called Wagemole (or PurpleDelta). In that operation, North Korean workers use fake or stolen identities to get legitimate jobs at companies, especially in the United States. They do this to earn money for North Korea and to spy on these organizations. This second operation has been going on since at least 2017.

While these are tracked as separate campaigns, researchers found significant connections between them, including shared tools, similar tactics, and overlapping computer infrastructure.

Why This Matters

What makes PurpleBravo especially dangerous is that job candidates often complete these fake coding tests on their employer’s computers. This means the malware gets installed directly into company networks, creating a serious security risk that goes beyond the well-known threat of North Korean workers infiltrating organizations.

Conclusion

AI used to code a malwareThe PurpleBravo campaign reveals how North Korean cyber operations continue to evolve and exploit trusted professional processes. By weaponizing the job interview process and development tools that companies use daily, these hackers have found an effective way to bypass traditional security measures. Organizations in the targeted industries should be extra cautious when conducting technical interviews with unknown candidates, especially those involving code execution. Companies should consider using isolated testing environments for candidate assessments and providing additional security training to hiring teams. As North Korean threat actors become more sophisticated in their social engineering tactics, the line between legitimate business operations and security threats continues to blur, making vigilance and updated security practices more critical than ever.