Fake Job Interviews Backdoor 30,000 Devices

The Register Security · High sophistication
Last updated September 21, 2026

An international advisory says North Korea–linked actors posing as recruiters tricked jobseekers into downloading “coding assignments” during fake interview processes. Opening the files installed backdoors and malware, enabling theft from over 7,000 crypto wallets and supporting at least $10.71M in stolen funds. The campaign also risks becoming a path into future employers if infected candidates later gain legitimate jobs.

How the attack worked

According to an international advisory, regime-backed actors posed as recruiters and targeted web designers, engineers, and cryptocurrency or Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims were instructed to download files presented as coding assignments or other recruitment tests. Opening these files backdoored the applicants' computers and installed malware, giving attackers a persistent foothold on personal devices used for job hunting.

The scale reported is significant: more than 30,000 devices were compromised, more than 7,000 cryptocurrency wallets were affected, and the advisory attributes at least $10.71 million in thefts to the campaign. Post-compromise activity included deploying remote access trojans and information stealers, enabling long-term access to credentials and other sensitive data.

Why it succeeded

The pretext exploited normal hiring behavior. Candidates expect to complete coding tests or technical assignments as part of an interview process, so a request to download and run a file did not stand out as unusual. Because the activity happened on personal, often unmanaged devices, there was little enterprise security tooling present to catch the malware before it executed.

What was stolen and why it matters

Stolen information included clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents. This data can support further impersonation and even extortion, extending the impact well beyond the initial device compromise. Compromised devices can also become an entry point into corporate systems once the jobseeker secures legitimate employment.

What to watch for

  • Unexpected requirements to download and run files for a coding test
  • File-based recruitment tests coming from an unverified source rather than a trusted coding platform
  • Pressure to complete hiring tasks through downloaded files instead of browser-based tools

Building resistance

Jobseekers should avoid downloading or opening interview assignments sent as files unless the sender and hiring process are verified through a trusted channel. Organizations should treat job-related requests for sensitive data as high risk and consider screening or controls for personal devices used in hiring workflows. Any organization suspecting it engaged a fraudulent worker should launch a full forensic investigation and assume credentials have been compromised.

Key findings

  • Regime-backed actors posed as recruiters and targeted “web designers, engineers, and cryptocurrency and Web3 specialists” with fake recruitment approaches.
  • Victims were told to download files presented as “coding assignments or other recruitment tests,” and opening them “backdoors the applicants' computers.”
  • The campaign compromised “more than 30,000 devices,” “more than 7,000 cryptocurrency wallets,” and attributed “at least $10.71 million in thefts.”
  • Post-compromise activity included deploying “remote access trojans (RATs) and information stealers,” enabling long-term access to “credentials and other sensitive data.”
  • Stolen information included “clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents,” which could enable “further impersonation” and even extortion.
  • Compromised personal devices can later become an entry point into corporate systems “when the jobseekers secure legitimate employment.”

Who’s being targeted

  • Commonly targeted roles: HR / Talent Acquisition, Hiring Managers, Engineering / Developers, Web/UX teams, Crypto/Web3 teams, IT/Security leadership.
  • Affected industries: Software/IT services, Web design and development, Cryptocurrency/Web3, Professional services.
  • Attack channels: email.
  • Impersonated: Recruiter / hiring team for a job opportunity.

Red flags to watch for

  • Unexpected requirement to download and run files for a ‘coding test’
  • File-based ‘recruitment test’ comes from an untrusted/unknown source
  • Pressure to complete tasks via downloaded files rather than trusted coding platforms
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers backdoor 30,000 devices through job interviews?

Actors posing as recruiters approached web designers, engineers, and crypto/Web3 specialists, then asked them to download files framed as coding assignments or recruitment tests. Opening these files backdoored the applicants' computers and installed malware.

What data did the attackers steal?

Post-compromise tooling included remote access trojans and information stealers that captured credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents.

Why does this matter for employers, not just jobseekers?

Compromised personal devices used during the hiring process may later provide a route into corporate systems once the jobseeker secures legitimate employment.

What should organizations do if they suspect a fraudulent hire?

The advisory recommends launching a full forensic investigation and assuming that credentials and other sensitive data have been compromised.

Read the video transcript

You get a dream interview for a Web3 role… then the recruiter emails you a “coding assignment” to download and run. In a real campaign, North Korea–linked recruiters did exactly this. Those 'tests' silently backdoored over 30,000 devices and drained more than 7,000 crypto wallets, about $10.7 million gone. Here’s the nasty twist: once that personal laptop is infected, it can follow you into your next job. When you log in at a new company, the RAT and info-stealer ride along, grabbing clipboard contents, passwords, even ID documents. Your move: if any recruiter sends a file you have to download and run as a 'coding test', stop. Don’t open it, contact our security team and the hiring contact through official channels and ask for a browser-based test instead.

Similar attacks

GhostCode Tricks Users Into Device-Code Login

GhostCode Tricks Users Into Device-Code Login

Researchers observed a real phishing campaign using a kit called GhostCode that abuses Microsoft’s legitimate “device code” sign-in flow to steal authentication tokens. Victims are socially engineered to open an NDA-themed HTML file and then enter a device code on Microsoft’s login page,…

September 18, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Iran Spyware Poses as Apps, Delivered by Message

Iran Spyware Poses as Apps, Delivered by Message

Government agencies say Iranian intelligence-linked attackers are targeting dissidents, journalists, and activists with Windows malware controlled through Telegram. The attack starts with a trust-building message impersonating someone the victim knows or app support, then delivers a file disguised…

September 15, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
M365 Direct Send Spoofs Internal HR & Finance

M365 Direct Send Spoofs Internal HR & Finance

Researchers observed a real phishing campaign that abused Microsoft 365’s “Direct Send” feature to deliver messages that looked like they came from trusted internal addresses (HR, accounting, admin). The emails commonly used familiar business lures like invoices, payment approvals, voicemail…

September 11, 2026