Fake Job Interviews Used to Breach 1,600 Firms

Wired Security · High sophistication
Last updated August 6, 2026

A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions, often through contractors who had broad access across multiple companies.

Key findings

  • A researcher reports evidence that 1,640 companies across 57 countries were impacted, with ~700–800 “really damaging” intrusions.
  • The primary initial lure described is fake job offers targeting software developers, followed by an “interview test” download that installs malware.
  • Contractors can create outsized risk because one compromised contractor may have access to many organizations.
  • The intruders were described as focusing heavily on cryptocurrency wallet access rather than broader data theft, though persistent access could be reused by other teams.

Who’s being targeted

  • Commonly targeted roles: Software Engineering, DevOps / Cloud, IT / Security, HR / Recruiting, Procurement / Vendor Management, All Contractors.
  • Affected industries: Cryptocurrency / fintech, Healthcare, Technology / software, Government / public sector, Banking, Telecommunications / device manufacturing.
  • Attack channels: email.
  • Impersonated: Recruiter / hiring manager for a fake job opening.

Awareness takeaways

  • Treat job-interview ‘coding tests’ that require downloading/running software as high-risk, and only use company-approved assessment methods.
  • Add specific training for developers and contractors on recruiting-themed social engineering, not just generic phishing.
  • Tighten contractor access: limit privileges, segment access by client, and rapidly revoke/rotate credentials when alerted.
  • Don’t assume attackers will ‘only’ target one asset type (like crypto); persistent access can be reused for broader espionage or data theft.

Red flags to watch for

  • Unusually high salary offer paired with urgency to run a program
  • Interview “test” requires downloading/running an executable instead of using a normal coding platform
  • Hiring process happens outside standard recruiting channels or avoids verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Developers are getting hacked by fake job interviews, over 1,600 companies hit from this one trick. The pitch is simple: a recruiter offers a high-salary dev role, then sends you an 'interview coding test' as a program to download and run. The moment you run it, malware installs silently. One compromised contractor laptop can expose keys and access to hundreds of client environments. If any interview asks you to download and run a coding test program, stop and report it to Security, use only company-approved assessment platforms.

Similar attacks

Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows…

July 20, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026