An international advisory says North Korea–linked actors posing as recruiters tricked jobseekers into downloading “coding assignments” during fake interview processes. Opening the files installed backdoors and malware, enabling theft from over 7,000 crypto wallets and supporting at least $10.71M in stolen funds. The campaign also risks becoming a path into future employers if infected candidates later gain legitimate jobs.
How the attack worked
According to an international advisory, regime-backed actors posed as recruiters and targeted web designers, engineers, and cryptocurrency or Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims were instructed to download files presented as coding assignments or other recruitment tests. Opening these files backdoored the applicants' computers and installed malware, giving attackers a persistent foothold on personal devices used for job hunting.
The scale reported is significant: more than 30,000 devices were compromised, more than 7,000 cryptocurrency wallets were affected, and the advisory attributes at least $10.71 million in thefts to the campaign. Post-compromise activity included deploying remote access trojans and information stealers, enabling long-term access to credentials and other sensitive data.
Why it succeeded
The pretext exploited normal hiring behavior. Candidates expect to complete coding tests or technical assignments as part of an interview process, so a request to download and run a file did not stand out as unusual. Because the activity happened on personal, often unmanaged devices, there was little enterprise security tooling present to catch the malware before it executed.
What was stolen and why it matters
Stolen information included clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents. This data can support further impersonation and even extortion, extending the impact well beyond the initial device compromise. Compromised devices can also become an entry point into corporate systems once the jobseeker secures legitimate employment.
What to watch for
- Unexpected requirements to download and run files for a coding test
- File-based recruitment tests coming from an unverified source rather than a trusted coding platform
- Pressure to complete hiring tasks through downloaded files instead of browser-based tools
Building resistance
Jobseekers should avoid downloading or opening interview assignments sent as files unless the sender and hiring process are verified through a trusted channel. Organizations should treat job-related requests for sensitive data as high risk and consider screening or controls for personal devices used in hiring workflows. Any organization suspecting it engaged a fraudulent worker should launch a full forensic investigation and assume credentials have been compromised.
Key findings
- Regime-backed actors posed as recruiters and targeted “web designers, engineers, and cryptocurrency and Web3 specialists” with fake recruitment approaches.
- Victims were told to download files presented as “coding assignments or other recruitment tests,” and opening them “backdoors the applicants' computers.”
- The campaign compromised “more than 30,000 devices,” “more than 7,000 cryptocurrency wallets,” and attributed “at least $10.71 million in thefts.”
- Post-compromise activity included deploying “remote access trojans (RATs) and information stealers,” enabling long-term access to “credentials and other sensitive data.”
- Stolen information included “clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents,” which could enable “further impersonation” and even extortion.
- Compromised personal devices can later become an entry point into corporate systems “when the jobseekers secure legitimate employment.”
Who’s being targeted
- Commonly targeted roles: HR / Talent Acquisition, Hiring Managers, Engineering / Developers, Web/UX teams, Crypto/Web3 teams, IT/Security leadership.
- Affected industries: Software/IT services, Web design and development, Cryptocurrency/Web3, Professional services.
- Attack channels: email.
- Impersonated: Recruiter / hiring team for a job opportunity.
Red flags to watch for
- Unexpected requirement to download and run files for a ‘coding test’
- File-based ‘recruitment test’ comes from an untrusted/unknown source
- Pressure to complete tasks via downloaded files rather than trusted coding platforms
Frequently asked questions
How did attackers backdoor 30,000 devices through job interviews?
Actors posing as recruiters approached web designers, engineers, and crypto/Web3 specialists, then asked them to download files framed as coding assignments or recruitment tests. Opening these files backdoored the applicants' computers and installed malware.
What data did the attackers steal?
Post-compromise tooling included remote access trojans and information stealers that captured credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents.
Why does this matter for employers, not just jobseekers?
Compromised personal devices used during the hiring process may later provide a route into corporate systems once the jobseeker secures legitimate employment.
What should organizations do if they suspect a fraudulent hire?
The advisory recommends launching a full forensic investigation and assuming that credentials and other sensitive data have been compromised.
Read the video transcript
You get a dream interview for a Web3 role… then the recruiter emails you a “coding assignment” to download and run. In a real campaign, North Korea–linked recruiters did exactly this. Those 'tests' silently backdoored over 30,000 devices and drained more than 7,000 crypto wallets, about $10.7 million gone. Here’s the nasty twist: once that personal laptop is infected, it can follow you into your next job. When you log in at a new company, the RAT and info-stealer ride along, grabbing clipboard contents, passwords, even ID documents. Your move: if any recruiter sends a file you have to download and run as a 'coding test', stop. Don’t open it, contact our security team and the hiring contact through official channels and ask for a browser-based test instead.