BlackTree Security · Infrastructure · Automation · AI

Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea’s Reach

The interview can look real, the company profile can survive a quick search and the coding exercise can resemble normal recruitment. WaterPlum weaponises all three. A new joint government advisory attributes the campaign to North Korean actors and puts a number on the accumulated reach: more than 30,000 devices, 7,000 cryptocurrency wallets and about $10.7 million transferred.

The Australian Cyber Security Centre advisory, issued with international partners, says the activity is commonly known as Contagious Interview. It targets technology professionals with job approaches, interviews and coding tasks that lead to malicious software or commands.

The figures describe a campaign, not one new breach

The device, wallet and transfer totals are official attributed estimates accumulated across the campaign. They should not be read as 30,000 devices compromised on 18 September, or as proof that every wallet lost funds. The advisory consolidates activity observed over time and gives defenders a common picture of the actor’s tradecraft.

Developers are valuable targets because their ordinary access may include source code, package registries, cloud environments, deployment systems and cryptocurrency projects. A personal device used for an interview can still hold browser sessions, SSH keys or credentials that reach the employer.

Recruitment trust replaces the exploit

The approach works because candidates expect to open repositories, run sample projects and troubleshoot audio or video. The attacker does not need a browser zero-day if the target willingly runs an untrusted dependency or copies a command into a terminal.

  • New recruiter profiles and plausible company pages create social proof.
  • Code challenges introduce repositories, packages or scripts that the candidate is expected to execute.
  • Video-call problems can justify installing a codec, extension or alternative application.
  • Follow-up access targets browser data, wallets, developer credentials and employer systems.

Separate interview work from trusted development

  • Use a disposable environment. Open unfamiliar recruitment code in an isolated virtual machine without work credentials or mounted secrets.
  • Do not install meeting fixes from a stranger. Use a known platform opened independently and decline unexpected codecs or extensions.
  • Inspect dependencies before execution. Treat package scripts, build hooks and copied terminal commands as code from an untrusted source.
  • Protect package publishing. Use phishing-resistant MFA and separate high-value maintainer credentials from everyday browsing.
  • Verify the organisation out of band. Contact the company through a domain and staff directory you found independently.
  • Report employer exposure quickly. If work credentials or repositories were present, personal cleanup alone is not enough.

The defensive boundary is not whether the recruiter sounds convincing. It is whether a recruitment interaction receives access to the same device, secrets and identities used to publish software or move money.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *