by

Fake job tests infect 30,000 PCs

Hackers from “best Korea” have infected more than 30,000 devices by posing as recruiters and handing developers malware disguised as coding tests.

According to TechSpot, authorities in Australia, Germany, Japan and the US have linked the campaign to a North Korean group known as WaterPlum, which has been targeting web designers, software engineers and people working in cryptocurrency and Web3.

The scam starts with what looks like a perfectly ordinary recruitment approach. Victims are contacted by supposed employers and asked to complete coding exercises or technical tests as part of an interview. Unfortunately, the job opportunity comes with rather more career development than advertised.

The files contain malware which, once opened, can install remote-access tools and information stealers. That gives attackers continued access long after the fake interview ends. The malware can harvest login credentials, clipboard contents, keystrokes, cryptocurrency wallet information and identity documents. Proprietary files can be taken too, turning an attack on one developer into a potential route into an employer or client.

Authorities said the campaign compromised more than 7,000 cryptocurrency wallets and generated at least $10.71 million in stolen cryptocurrency, which investigators said was ultimately sent to North Korea. WaterPlum can use stolen credentials to raid wallets or get at personal and corporate information. Sensitive material may be useful for extortion, while stolen identity documents have another value entirely.

Investigators warned that North Korean IT workers can use stolen identities when applying for jobs overseas, helping them conceal where they are actually working from. That ties WaterPlum into a much wider North Korean operation in which remote IT workers use false identities to obtain jobs with companies in countries enforcing sanctions against Pyongyang.

Researchers estimate about 100,000 North Korean IT workers are employed or seeking work around the world. The operation could be generating more than $500 million a year for North Korea. Some workers use laptop farms run by accomplices so corporate systems think they are connecting from the country where they were supposedly hired.

Others have reportedly turned to AI face-swapping software during video interviews, because apparently fake CVs and stolen identities were no longer complicated enough. Companies have been warned to watch for candidates whose impressive CVs fail to survive technical questioning, persistent problems with video calls or unusual demands to be paid in cryptocurrency.

Authorities recommend a full forensic investigation if a company discovers it has hired a fraudulent North Korean worker, assuming passwords and sensitive systems may already have been compromised.

 

 

TOPICS:
coding tests  ·  Contagious Interview  ·  crypto wallets  ·  cryptocurrency  ·  Cyber security  ·  fake job interviews  ·  identity theft  ·  IT workers  ·  malware  ·  North Korea  ·  North Korean hackers  ·  remote access trojan  ·  software developers  ·  WaterPlum  ·  web3

Latest articles

Share

Featured articles

AINews

Hot topics

No results found.

Latest reviews