Authorities say a North Korean group posed as recruiters and ran fake technical interviews to convince job seekers to execute malicious code. The operation infected over 30,000 devices, led to thousands of compromised cryptocurrency wallets, and allegedly generated over $10 million for North Korea.
Key findings
- A North Korean-linked group posed as recruiters to target job seekers during fake technical interviews.
- Victims were instructed to run malicious code, leading to more than 30,000 infected devices across 100+ countries.
- Investigators report 7,000+ compromised cryptocurrency wallets and at least $10.71M funneled to North Korea.
- Authorities say a laptop farm in Japan supporting the scheme was dismantled.
Who’s being targeted
- Commonly targeted roles: All employees (especially active job seekers), Engineering/Developers, IT, HR/Recruiting, Finance/Crypto users.
- Affected industries: Cryptocurrency/Blockchain, Job seekers/Recruitment, Technology (general).
- Attack channels: vishing.
- Impersonated: Recruiter / hiring team for a job opportunity.
Awareness takeaways
- Treat unsolicited recruiter outreach as untrusted until verified through an independent channel (e.g., company career site or known corporate contacts).
- Never run commands, scripts, or “test projects” sent during interviews unless they come through a verified, company-controlled process and have been vetted.
- Crypto and financial accounts should be considered high-risk targets; add extra verification and monitoring if you use crypto wallets for work or personal finances.
Red flags to watch for
- Unusual request to run code outside a standard, trusted interview platform
- Pressure to execute commands quickly during an interview
- Interview process involves downloading/running unexpected tools or scripts
Read the video transcript
Job hunting? Imagine a recruiter interview that secretly installs malware on your laptop. Authorities say a North Korea–linked group posed as recruiters, ran fake technical interviews, and had job seekers run malicious code, infecting over 30,000 devices and draining more than 7,000 crypto wallets. Here’s the trick: during the call, the "recruiter" sends you a script or command, pushes you to run it fast, and it’s not in a standard platform like HackerRank, Codility, or the company’s own coding tool. If any recruiter ever asks you to run code or tools they send, stop and verify the job and interview through the company’s official careers site before you touch a single command.