Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea’s Reach

The coding test was the payload. Officials say the developer-focused campaign accumulated more than $10.7 million in transfers.

The coding test was the payload. Officials say the developer-focused campaign accumulated more than $10.7 million in transfers.

Two South Korean organisations kept serving traffic through HAProxy while a hidden plugin stole credentials, hijacked sessions and altered pages for selected visitors.

Most security teams are trained to look for attackers entering an organisation. Malware arrives. Credentials are stolen. A vulnerability is exploited. A suspicious login appears. The North Korean remote IT worker programme takes a different route. The attacker applies for…

Microsoft’s August 2026 updates fix a WinSock privilege-escalation flaw used by North Korea’s Lazarus group against defence, aerospace and aviation organisations. The exploit helped Operation Dream Job turn a local Windows foothold into SYSTEM access, deploy a kernel rootkit and interfere with endpoint-security controls.