More

    Fake IT Job Interviews Help North Korea Steal Millions in Crypto


    Key Takeaways

    Fake Job Interviews Used as Bait

    A North Korean cyberattack campaign disguised as legitimate tech recruitment has infected more than 30,000 computers across at least 100 countries, stealing thousands of cryptocurrency wallets and millions of dollars to fund Pyongyang’s weapons programs, law enforcement agencies from six nations warned.

    In a joint security advisory issued Sept. 18, Japan’s National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI), alongside cyber and intelligence agencies from Australia and Germany, detailed the global operations of a threat actor known as “Waterplum,” also tracked internationally as “Contagious Interview.”

    Authorities assessed that Waterplum and associated North Korean IT workers operate under the direct oversight of Bureau 313 of the Munitions Industry Department of the Workers’ Party of Korea, which manages North Korea’s military research and weapons production.

    According to Japanese investigators, Waterplum targeted software developers, web designers, and cryptocurrency specialists on job platforms and social media by posing as recruiters from legitimate artificial intelligence, blockchain, and tech recruitment companies.

    During fake technical interviews or coding assessments, target candidates were instructed to download malicious software disguised as coding tests or video conferencing troubleshooting tools. Once executed, the code delivered backdoor trojans and information-stealing malware, allowing hackers to harvest personal identification documents and cryptocurrency private keys.

    Between late 2025 and July 2026, the campaign compromised at least 30,000 devices worldwide, compromising more than 7,000 cryptocurrency wallets and funneling at least 1.7 billion yen ($10.71 million) in digital assets into North Korean-controlled wallets, officials said.

    ‘Laptop Farms’ Uncovered in Japan

    The investigation also highlighted the role of “domestic enablers” who helped North Korean operatives bypass location verification and land outsourced IT jobs at Japanese and U.S. firms.

    In a first for Japanese law enforcement, police seized and dismantled a local “laptop farm” that permitted remote North Korean IT workers to operate under local IP addresses. Authorities noted that illicit IT workers operating through these schemes transferred hundreds of millions of yen worth of crypto assets overseas.

    International security agencies urged tech companies and gig workers to exercise caution during online interviews, avoid executing unvetted code outside isolated sandbox environments, and utilize workspace restriction controls when opening untrusted code repositories.



    Source link

    Latest stories

    You might also like...