A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions, often through contractors who had broad access across multiple companies.
Key findings
- A researcher reports evidence that 1,640 companies across 57 countries were impacted, with ~700–800 “really damaging” intrusions.
- The primary initial lure described is fake job offers targeting software developers, followed by an “interview test” download that installs malware.
- Contractors can create outsized risk because one compromised contractor may have access to many organizations.
- The intruders were described as focusing heavily on cryptocurrency wallet access rather than broader data theft, though persistent access could be reused by other teams.
Who’s being targeted
- Commonly targeted roles: Software Engineering, DevOps / Cloud, IT / Security, HR / Recruiting, Procurement / Vendor Management, All Contractors.
- Affected industries: Cryptocurrency / fintech, Healthcare, Technology / software, Government / public sector, Banking, Telecommunications / device manufacturing.
- Attack channels: email.
- Impersonated: Recruiter / hiring manager for a fake job opening.
Awareness takeaways
- Treat job-interview ‘coding tests’ that require downloading/running software as high-risk, and only use company-approved assessment methods.
- Add specific training for developers and contractors on recruiting-themed social engineering, not just generic phishing.
- Tighten contractor access: limit privileges, segment access by client, and rapidly revoke/rotate credentials when alerted.
- Don’t assume attackers will ‘only’ target one asset type (like crypto); persistent access can be reused for broader espionage or data theft.
Red flags to watch for
- Unusually high salary offer paired with urgency to run a program
- Interview “test” requires downloading/running an executable instead of using a normal coding platform
- Hiring process happens outside standard recruiting channels or avoids verification
Read the video transcript
Developers are getting hacked by fake job interviews, over 1,600 companies hit from this one trick. The pitch is simple: a recruiter offers a high-salary dev role, then sends you an 'interview coding test' as a program to download and run. The moment you run it, malware installs silently. One compromised contractor laptop can expose keys and access to hundreds of client environments. If any interview asks you to download and run a coding test program, stop and report it to Security, use only company-approved assessment platforms.