Forgot your password?
typodupeerror
Crime IT

North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide (inc.com) 27

"I would like to verify your technical abilities, so please download the specified file and complete the assigned task..."

Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage...

The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said.

The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said.

The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.."

Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible."

The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities."

North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide

Comments Filter:
  • by evil_aaronm ( 671521 ) on Monday September 21, 2026 @01:58AM (#66345434)
    If your first thought after "please download the specified file and complete the assigned task" isn't "Hahahahaha - no," then you're either a fool, or very desperate. And if you're desperate, I'm sorry for you, man. Shit's fkd up. I hope things turn out better for you.
    • by geekmux ( 1040042 ) on Monday September 21, 2026 @02:10AM (#66345436)

      If your first thought after "please download the specified file and complete the assigned task" isn't "Hahahahaha - no," then you're either a fool..

      Dare we test LinkedIn prevalence to see just how many foolish recruiters see how 'funny' that is? Seems this comes in the form of 'homework' assignments from recruiters/potential employers these days. Hackers saw a golden opportunity to exploit.

      (LinkedIn Virgin) "The hell, is that stench.."

      (Veteran with 866 application deaths) "Desperation. The onsite distillery turns it into a cologne we all wear now. Choice? Hahahahaha - no. We don't."

      * submits application #867 *

      • Seriously, how is a job applicant supposed to be able to distinguish what a hacker asks them to do versus the typical humiliation ritual that passes for the standard employment experience we are accustomed to?

        It's two slightly different flavors of abuse.

    • by Zarhan ( 415465 ) on Monday September 21, 2026 @04:57AM (#66345506)

      They are a *bit* more sophisticated than that. Basically, they are saying "here's a ZIP, it's just a git repository" - essentially, they are saying that here's a git bundle for you (instead of exposing that to Internet and asking you to do a git clone).

      What happens then is that you unpack that repository, do your changes, and then do a git commit for the "assignment" they put up for posterity.

      But then the pre-commit hook that they have configured fires and runs some binary blob that was included in the repository. This would of course not happen with a git clone, but when you just download an innocent-looking ZIP that has a src/ and .git/ subdirectories and git log shows "Version for applicant interviews"...you might be fooled.

      So it's not just "yeah download this .EXE and allow it to run as admin okthxbye".

      • I don't think that's where they were going with that. As I read it, if you're being assigned homework before you even get an interview, you're in a trap at best.

        • by pla ( 258480 )
          I've had interviews where they wanted me to complete a toy problem (like FizzBuzz) just to confirm yes, I can code my way out of a paper bag.

          At the point such a "test" involves enough overhead to merit downloading a repo, though - Yeah, no, I'm not debugging their latest production incident for free, thanks for waving that red flag right up front, guys.
          • Exactly, a few questions or a short exercise to ensure that you have the basic skills required to do the job is one thing, this was masquerading as something else, specifically something no serious employer would do except to make people go away

    • by rsilvergun ( 571051 ) on Monday September 21, 2026 @10:29AM (#66345766)
      It doesn't matter if it smells like a scam if you've been unemployed for 6 months and you've run out of things to sell.

      We have 25% functional unemployment. That means a quarter of the population even if they have a job cannot support themselves. Some of them are living with relatives some of them have six or seven roommates and the rest are homeless living out of cars or under bridges. We have half a million homeless people working full-time. Probably more that's an old statistic and the economy is in freefall.

      You're going to start seeing more and more breakdown in places. Eventually the combination of incompetent leadership from known child sex predators combined with a massive push for automation in a world where if you don't work you don't eat is going to start eroding the tax base and the consumer spending bases to the point where we will not be able to maintain an economy. At least not a consumer based economy like we have now. Change will be inevitable and we aren't going to accept people sitting around eating bonbons and playing Xbox without working but we're not going to have anything useful for them to do and we're not going to let the government give them something useful to do.

      When the tax base collapses police and fire will get shut down.

      And remember no matter how good a shot you are you're going to run out of ammo before the world runs out of desperate people with nothing to lose
    • I've had otherwise legitimate interviewers where they wanted me to access some weird website or install an app on my phone.
      My current employer we use some interview software that tracks the desktop focus to help identify if someone is cutting and pasting into search engines or AI. Not fool proof, but there are plenty of people that didn't realize they granted some key permissions when they signed into the website.
      I think it's somewhat invasive, but I just work here and do what they tell me.

    • by cowwoc2001 ( 976892 ) on Monday September 21, 2026 @11:57PM (#66346466)

      It's not so simple. They was actually "interviewed" by these guys last week.

      The "recruiter" asks the candidate to clone a GitHub project and open it using Cursor. It doesn't look like you're running anything. You're just opening a project file.

      The Cursor installation is legit (downloaded from the official location) and the GitHub repository is 99% source-code so it doesn't look harmful. The problem is that the repository contains a Cursor-specific configuration file that downloads and runs a binary when the project is opened.

      These AI tools are not very smart, to say the least. In any case, luckily my antivirus blocked the operation; otherwise, I wouldn't have noticed.

    • by mjwx ( 966435 )

      If your first thought after "please download the specified file and complete the assigned task" isn't "Hahahahaha - no," then you're either a fool, or very desperate. And if you're desperate, I'm sorry for you, man. Shit's fkd up. I hope things turn out better for you.

      It's not just desperation but also greed. Especially in countries where workers don't have many rights and a lot of costs like the US.

      Greed is the most successful attack vector in most scams. The temptation of more money tends to blind even some of the most astute people, especially in a mercenary culture.

  • by Quakeulf ( 2650167 ) on Monday September 21, 2026 @06:16AM (#66345554)

    I've applied for over 1000 jobs the past two years and I only get automatically discarded upon clicking "Submit". I wonder what it would take for me to get scammed like this. Please help, I want some excitement in my life.

  • There is a whole generation that had phones as kids, They were constantly bombarded with prompts to install this or that app. For the most part the apps are "safe" as in the person never actually encountered what they would consider to be a negative result.

    People under 30 pretty much install anything. They don't even think about it. Even IT educated ones do it.

    In today's age you a strong armed into installing apps for McDonalds, that delivery service, to rent a bike in the city, to get on the train, to

Real Users are afraid they'll break the machine -- but they're never afraid to break your face.

Working...