Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CVE-2023-XXXXX: Critical Windows Defender DoS Vulnerability Patched
September 21, 2026
Critical cPanel Vulnerability CVE-2026-41940 Exploited to Deploy Mirai Malware
September 21, 2026
Blockchain-based Malware Steals Bank Logins and 2FA Codes
September 21, 2026
Home/CyberSecurity News/North Korean Hackers Use Fake Job Interviews to Infect 30,000 PCs, Steal $10.7M Crypto
CyberSecurity News

North Korean Hackers Use Fake Job Interviews to Infect 30,000 PCs, Steal $10.7M Crypto

Key Takeaways North Korean-linked threat actors, collectively known as WaterPlum and operating under the campaign name “Contagious Interview,” have exploited fake job interviews to infect...

Emy Elsamnoudy
Emy Elsamnoudy
September 21, 2026 5 Min Read
2 0

Key Takeaways

  • North Korean-linked threat actors, collectively known as WaterPlum and operating under the campaign name “Contagious Interview,” have exploited fake job interviews to infect over 30,000 computers across more than 100 countries.
  • The campaign, active from December 2025 to July 2026, resulted in the theft of approximately $10.7 million in cryptocurrency from over 7,000 digital wallets.
  • Targets were primarily software developers, lured into downloading and executing malicious files disguised as coding tasks or interview software.
  • The attack not only compromises individual systems and crypto wallets but also poses a significant supply chain risk by using compromised developers as entry points to their employers’ or clients’ networks.
  • The threat actors utilized sophisticated tactics, including AI face-swapping during video interviews and the operation of “laptop farms” to obscure their true location.

A sophisticated cybercrime operation attributed to North Korean state-sponsored hackers, known as WaterPlum, has successfully compromised more than 30,000 personal computers across over 100 nations. This extensive campaign, dubbed “Contagious Interview,” leveraged convincing fake job interviews to trick software developers into installing malware, leading to the theft of an estimated $10.7 million in cryptocurrency from over 7,000 digital wallets. The attacks took place between December 2025 and July 2026.

Table Of Content

  • Key Takeaways
  • North Korean WaterPlum Hackers Infect 30,000 PCs
  • Laptop Farms Broaden Risk
  • What You Should Do
  • Indicators of Compromise (IoCs)

The Internet Crime Complaint Center (IC3) has highlighted this deceptive tactic in its guidance regarding North Korean IT worker activities. According to an IC3 report, threat actors are exploiting the trust inherent in hiring processes to implant malicious software onto systems containing sensitive data.

Beyond direct financial theft, the campaign introduces a critical secondary risk: a compromised developer can inadvertently become a conduit for further intrusions into their employer’s or client’s networks. Stolen data, including browser login credentials, cryptocurrency wallet keys, identity documents, screenshots, and project files, can facilitate future theft, extortion attempts, or direct access to corporate infrastructures.

North Korean WaterPlum Hackers Infect 30,000 PCs

The WaterPlum group initiates contact with potential victims through various platforms, including social media, professional job boards, and freelance marketplaces. They impersonate legitimate employers and then instruct candidates to complete a simulated coding challenge or troubleshoot a fabricated issue with interview software. This approach mirrors other “fake recruiter” schemes where a standard technical assessment is weaponized.

Instead of a benign task, candidates are directed to download and execute a malicious project, software package, or file. These files are typically laden with various malware strains, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. These tools are designed to establish initial footholds, maintain persistent remote access, and exfiltrate sensitive information from infected systems.

One notable malware, StoatWaffle, can be embedded within projects themed around blockchain technology. It exploits a specific Visual Studio Code configuration to execute malicious code automatically when a victim opens and “trusts” the project folder. The attackers have also been observed employing advanced social engineering techniques, such as AI face-swapping during video interviews, to enhance their credibility. This tactic underscores that even a seemingly professional recruitment process does not guarantee the safety of downloaded content.

The repercussions of such compromises extend far beyond individual financial losses. Credentials pilfered from developers can expose entire organizations—employers, clients, or contractors—to intellectual property theft and widespread network breaches. Furthermore, stolen identity documents could enable North Korean IT workers to assume false identities, securing legitimate contracts and generating foreign income for the regime.

Laptop Farms Broaden Risk

Authorities have connected segments of this illicit activity to North Korean IT workers who operate under fabricated identities. These individuals utilize “laptop farms”—physical locations equipped with numerous computers managed remotely—alongside virtual private servers and local facilitators to obscure their true geographic location. This infrastructure allows them to conduct their malicious operations while maintaining a facade of legitimacy.

An advisory detailed how Japanese authorities dismantled a laptop farm linked to one such enabler. Investigations revealed that WaterPlum operatives and suspected North Korean IT workers used identical IP addresses when accessing these laptop farms, interacting with crowdsourcing services, and even applying for positions at a Japanese cryptocurrency exchange. This overlap provided crucial evidence linking the various activities.

What You Should Do

  • For Employers:
    • Scrutinize unusual recruitment details and treat them as potential security threats.
    • Verify all contact information for recruiters and applicants independently.
    • Encourage in-depth discussions with candidates about their experience to detect inconsistencies.
    • Remain vigilant for discrepancies in claimed skills, location, language proficiency, or payment requests.
    • Implement robust vetting processes for all contractors and employees, especially those with privileged access.
    • Limit contractor access to essential resources and revoke accounts and sessions immediately upon suspicion.
  • For Candidates/Developers:
    • Never execute unknown code on personal devices or systems containing cryptocurrency, sensitive data, or corporate access.
    • Always test untrusted projects or code in an isolated, sandboxed environment.
    • Thoroughly inspect all downloaded files and projects for obfuscated or unreadable content.
    • When using Visual Studio Code, avoid opening unfamiliar projects outside of Restricted Mode.
    • If you suspect an infection, immediately disconnect the device from the internet.
    • In case of suspected wallet compromise, create a new wallet on a separate, clean device, transfer all assets, store the new seed phrase offline, back up critical files, and perform a full system reset on the compromised machine.

This campaign underscores a persistent threat to developers: the allure of a promising job opportunity can normalize risky behavior, such as downloading and executing untrusted code. This method is analogous to other malware campaigns, like the broader Contagious Interview operation, which similarly exploits the hiring process to deliver credential-stealing software.

Indicators of Compromise (IoCs)

Type Indicator Description
Malware family BeaverTail JavaScript-based malware delivered through malicious packages and developer projects
Malware family InvisibleFerret Python-based backdoor used to access compromised systems
Malware family OtterCookie JavaScript remote-access and information-stealing malware
Malware family OtterCandy Malware combining OtterCookie and RATatouille capabilities
Malware family StoatWaffle Modular Node.js loader, credential harvester and remote-access malware
File name .vscode/tasks.json Visual Studio Code task configuration file that can trigger malicious code execution when an unsafe project folder is trusted
Suspicious command string curl Command string cited by the advisory as a warning sign in untrusted scripts
Suspicious command string base64 String that can indicate encoded or concealed script content
Suspicious command string -enc Common encoded-command parameter cited in the advisory
Suspicious command string mshta Script execution utility cited as a suspicious string in unknown commands
Suspicious command string Invoke-WebRequest -Uri Download command pattern that should be reviewed before execution
Suspicious command string iwr -uri Shortened download-command pattern cited in the advisory
Suspicious command string hidden String that can indicate an attempt to conceal command execution

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical OpenAI Codex Sandbox Flaws Let Attackers Execute Commands

Next Post

Blockchain-based Malware Steals Bank Logins and 2FA Codes

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top 10 Identity Governance & Administration (IGA) Tools for 2026
September 21, 2026
Top 10 Best Single Sign-On (SSO) Solutions in 2024
September 21, 2026
Best Multi-Factor Authentication (MFA) Solutions for 2026
September 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us