NK Fake Recruiters Trick Job Seekers Into Malware

About DFIR · High sophistication
Last updated September 21, 2026

Authorities say a North Korean group posed as recruiters and ran fake technical interviews to convince job seekers to execute malicious code. The operation infected over 30,000 devices, led to thousands of compromised cryptocurrency wallets, and allegedly generated over $10 million for North Korea.

Key findings

  • A North Korean-linked group posed as recruiters to target job seekers during fake technical interviews.
  • Victims were instructed to run malicious code, leading to more than 30,000 infected devices across 100+ countries.
  • Investigators report 7,000+ compromised cryptocurrency wallets and at least $10.71M funneled to North Korea.
  • Authorities say a laptop farm in Japan supporting the scheme was dismantled.

Who’s being targeted

  • Commonly targeted roles: All employees (especially active job seekers), Engineering/Developers, IT, HR/Recruiting, Finance/Crypto users.
  • Affected industries: Cryptocurrency/Blockchain, Job seekers/Recruitment, Technology (general).
  • Attack channels: vishing.
  • Impersonated: Recruiter / hiring team for a job opportunity.

Awareness takeaways

  • Treat unsolicited recruiter outreach as untrusted until verified through an independent channel (e.g., company career site or known corporate contacts).
  • Never run commands, scripts, or “test projects” sent during interviews unless they come through a verified, company-controlled process and have been vetted.
  • Crypto and financial accounts should be considered high-risk targets; add extra verification and monitoring if you use crypto wallets for work or personal finances.

Red flags to watch for

  • Unusual request to run code outside a standard, trusted interview platform
  • Pressure to execute commands quickly during an interview
  • Interview process involves downloading/running unexpected tools or scripts
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Job hunting? Imagine a recruiter interview that secretly installs malware on your laptop. Authorities say a North Korea–linked group posed as recruiters, ran fake technical interviews, and had job seekers run malicious code, infecting over 30,000 devices and draining more than 7,000 crypto wallets. Here’s the trick: during the call, the "recruiter" sends you a script or command, pushes you to run it fast, and it’s not in a standard platform like HackerRank, Codility, or the company’s own coding tool. If any recruiter ever asks you to run code or tools they send, stop and verify the job and interview through the company’s official careers site before you touch a single command.

Similar attacks

Fake AI Recruiters Hit 30K Devices Worldwide

Fake AI Recruiters Hit 30K Devices Worldwide

A weekly threat bulletin highlights a North Korea–linked campaign where attackers posed as AI or blockchain employers to trick IT professionals into getting infected and losing cryptocurrency. It also notes a phishing kit that abuses Microsoft’s legitimate device login flow to gain long-lasting…

September 22, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Fake Mexico ID Site Pushed WebDAV Malware

Fake Mexico ID Site Pushed WebDAV Malware

Researchers found an exposed malware delivery server that contained phishing lures, testing notes, and live delivery logs for an active campaign. The live operation targeted Windows users in Mexico using a fake government ID (CURP) lookup site that triggered a WebDAV-based download flow and…

July 20, 2026