Fake Job Interviews Used to Breach 1,600 Firms

Wired Security · High sophistication
Last updated August 6, 2026

A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions, often through contractors who had broad access across multiple companies.

Key findings

  • A researcher reports evidence that 1,640 companies across 57 countries were impacted, with ~700–800 “really damaging” intrusions.
  • The primary initial lure described is fake job offers targeting software developers, followed by an “interview test” download that installs malware.
  • Contractors can create outsized risk because one compromised contractor may have access to many organizations.
  • The intruders were described as focusing heavily on cryptocurrency wallet access rather than broader data theft, though persistent access could be reused by other teams.

Who’s being targeted

  • Commonly targeted roles: Software Engineering, DevOps / Cloud, IT / Security, HR / Recruiting, Procurement / Vendor Management, All Contractors.
  • Affected industries: Cryptocurrency / fintech, Healthcare, Technology / software, Government / public sector, Banking, Telecommunications / device manufacturing.
  • Attack channels: email.
  • Impersonated: Recruiter / hiring manager for a fake job opening.

Awareness takeaways

  • Treat job-interview ‘coding tests’ that require downloading/running software as high-risk, and only use company-approved assessment methods.
  • Add specific training for developers and contractors on recruiting-themed social engineering, not just generic phishing.
  • Tighten contractor access: limit privileges, segment access by client, and rapidly revoke/rotate credentials when alerted.
  • Don’t assume attackers will ‘only’ target one asset type (like crypto); persistent access can be reused for broader espionage or data theft.

Red flags to watch for

  • Unusually high salary offer paired with urgency to run a program
  • Interview “test” requires downloading/running an executable instead of using a normal coding platform
  • Hiring process happens outside standard recruiting channels or avoids verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Developers are getting hacked by fake job interviews, over 1,600 companies hit from this one trick. The pitch is simple: a recruiter offers a high-salary dev role, then sends you an 'interview coding test' as a program to download and run. The moment you run it, malware installs silently. One compromised contractor laptop can expose keys and access to hundreds of client environments. If any interview asks you to download and run a coding test program, stop and report it to Security, use only company-approved assessment platforms.

Similar attacks

Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows…

July 20, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026