Skip to content
Tech News
← Back to articles

Hackers use fake coding tests to infect 30,000 devices and steal $10 million in crypto

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

This story highlights how North Korean state-linked hackers are exploiting the tech hiring process itself, using fake job interviews to distribute malware that steals cryptocurrency and sensitive data. It underscores a growing threat to both individual job seekers and their employers, as compromised devices can expose corporate networks and trade secrets, all while funneling stolen funds to a sanctioned regime.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — With fake job-offer malware campaigns stealing credentials and crypto-wallet data, hardware-based two-factor authentication like a YubiKey adds a critical layer of protection that malware can't easily bypass, even if your login info gets stolen. It's a simple, tangible way for developers and crypto users to harden their accounts against exactly this kind of credential-theft attack.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Bottom line: North Korean cybercriminals are using fake job offers to infect the computers of technology workers, steal cryptocurrency and collect information that can be used in later attacks. Authorities in Australia, Germany, Japan and the United States said the operation has compromised more than 30,000 devices and more than 7,000 cryptocurrency wallets. The campaign has generated at least $10.71 million, which investigators said was ultimately directed to North Korea.

The agencies refer to the group behind the activity as WaterPlum. It targets web designers, software engineers and people working in cryptocurrency and Web3. The group contacts victims while posing as recruiters, then sends what appears to be a coding exercise or other technical test as part of the hiring process.

The files contain malware. Once a target downloads and opens one, the attackers can install remote-access tools and information stealers on the computer. That gives them continuing access to the system after the supposed interview is over.

The malware can collect login credentials, clipboard data, keystrokes, cryptocurrency-wallet information, identity documents and proprietary files. The risk can extend to a victim's employer if the person later uses the compromised computer for legitimate work.

The agencies said stolen identity documents may also help North Korean IT workers conceal their identities while seeking jobs abroad. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory said.

The stolen credentials can be used to take cryptocurrency, access personal data or obtain trade secrets from employers, clients and contractors, the advisory said. The attackers may also use sensitive material in extortion attempts.

The campaign is tied to a wider North Korean effort to generate money through remote IT work. In that scheme, North Korean workers use false identities to get jobs with companies in the US and other countries that sanction North Korea. They collect salaries, with much of the money going back to the government.

Researchers estimate that about 100,000 North Korean IT workers are employed or looking for work around the world. Some use laptop farms operated by accomplices to make it appear they are working from the country where they were hired. These activities may bring in more than $500 million a year for North Korea.

Companies have grown more familiar with signs that a job candidate may be using a false identity. Applicants may present impressive résumés that do not match their performance in interviews. Some refuse to meet in person, have repeated technical issues during video calls or ask to be paid in cryptocurrency.

North Korean workers may also use AI face-swapping tools during interviews. The software can leave visual glitches, and some candidates turn off their cameras shortly after a call begins.

... continue reading