North Korean Hackers Target Job Seekers with Fake Recruiter Scam
A North Korean hacking group called WaterPlum has compromised over 30,000 devices in more than 100 countries, according to a joint advisory from Japanese, US, Australian, and German authorities. The group, also known as Contagious Interview, targets software developers and IT professionals worldwide by posing as recruiters offering attractive job opportunities.
WaterPlum's scam involves fake interviews and requests for job seekers to download and run malicious files hosted on developer platforms and code repositories. During the interviews, the hackers instruct victims to complete a coding assignment or troubleshoot a video conferencing issue, which allows them to install malware and exfiltrate sensitive data and cryptocurrency.
The stolen data can include login credentials, clipboard information, keylogs, screenshots, and files stored on a PC or in shared folders. The advisory warns that the actors can use this stolen sensitive information for extortion. At least $10.71 million has been stolen through this scheme and transferred to North Korea.