|
North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide"I would like to verify your technical abilities, so please download the specified file and complete the assigned task..."
Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities, including the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center... The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage... The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software. Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target's employer, opening the door to intellectual-property theft and espionage, authorities said. The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said. The malicious files are "hosted on multiple online collaboration software developer platforms and code repositories," the advisory points out, and includes malicious Node Package Manager (NPM) packages.." Stolen ID images can also be used by North Korean IT workers to impersonate victims to obtain contracts and receive payment in foreign currency, but "The actors can also use stolen sensitive information for extortion." In one case, a North Korean IT worker "extorted a company over payment and published its proprietary source code online. In another case, an IT Worker hired for website maintenance defaced the hiring company's website and rendered the site inaccessible." The advisory provides clues for employers. It warns these malicious IT workers "tend to favor payment in cryptocurrency, and they may request that remuneration be sent to an account in another person's name." During interviews they'd sometimes used Al face-swapping software, then claimed network issues and disabled their video. And "On holidays celebrated in North Korea, the actors played games and watched soccer videos instead of conducting their usual malicious activities." Read more of this story at Slashdot. |
|
Our Privacy Policy can be viewed at https://freeinternetpress.com/privacy_policy.php FIP XML/RSS/RDF Newsfeed Syndication https://freeinternetpress.com/rss.php © 2026 FreeInternetPress.com Free Internet Press is licensed under a Creative Commons Attribution 3.0 United States License. You may reuse or distribute original works on this site, with attribution per the above license. Any mirrored or quoted materials may be copyright their respective authors, publications, or outlets, as shown on their publication, indicated by the link in the news story. Such works are used under the fair use doctrine of United States copyright law. Should any materials be found overused or objectionable to the copyright holder, notification should be sent to [email protected], and the work will be removed and replaced with such notification. Please email [email protected] with any questions. |
|