North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide – Slashdot

- Advertisement -spot_imgspot_img
- Advertisement -spot_imgspot_img

“I would like to verify your technical abilities, so please download the specified file and complete the assigned task…”

Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports:


The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department’s Cyber Crime Center… The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage…

The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target’s employer, opening the door to intellectual-property theft and espionage, authorities said.

The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said.

The malicious files are “hosted on multiple online collaboration software developer platforms and code repositories,” the advisory points out, and includes malicious Node Package Manager (NPM) packages..”

Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but “The actors can also use stolen sensitive information for extortion.” In one case, a North Korean IT worker “extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.”

The advisory provides clues for employers. It warns these malicious IT workers “tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person’s name.” During interviews they’d sometimes used Al face-swapping software, then claimed network issues and disabled their video. And “On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities.”

Source link

- Advertisement -spot_imgspot_img

Highlights

- Advertisement -spot_img

Latest News

- Advertisement -spot_img