North Korean Hackers Deploy Fake Job Interview Scam to Infect Tens of Thousands of Devices
Authorities in Japan and the United States disclosed on September 18 that a sophisticated cyber‑espionage operation linked to the North Korean group known as WaterPlum has compromised more than 30,000 computers worldwide by disguising malware as a job interview invitation.
The campaign, dubbed "Contagious Interview," lured victims through a seemingly legitimate recruitment email that promised an online interview. Recipients who clicked the embedded link unwittingly downloaded a malicious payload, which then spread laterally across networks, harvesting credentials and exfiltrating data.
Coordinated investigations by Japan's National Police Agency, the FBI, the Department of Defense Cyber Crime Center and several allied intelligence services traced the infrastructure back to WaterPlum, a unit previously associated with financially motivated attacks and intelligence‑gathering for Pyongyang. While the group has traditionally focused on cryptocurrency theft and ransomware, this operation marks a notable shift toward targeted social engineering aimed at recruiting unwitting participants in a broader espionage effort.
Security analysts note that the use of a job interview as a lure is particularly effective because it exploits the high demand for employment in many regions, especially among younger, tech‑savvy users. The malicious code employed in the operation is believed to be a variant of the well‑known Remote Access Trojan (RAT) used by other North Korean actors, capable of keylogging, screen capture and remote command execution.
Officials warned that the infection could have far‑reaching consequences for both private firms and government agencies, as the harvested credentials may grant attackers access to sensitive internal systems. The multi‑national response aims to contain the spread, issue remediation guidance, and identify any data that may have been exfiltrated.
Cybersecurity experts say the incident underscores the growing sophistication of state‑backed threat groups and the importance of robust email security hygiene. Users are urged to verify the authenticity of recruitment communications, avoid downloading attachments or clicking links from unknown senders, and ensure that endpoint protection solutions are up‑to‑date. Ongoing investigations will continue to map the full scope of the breach and assess potential links to other recent North Korean cyber campaigns.
Comments (0)
Be the first to comment.
Join the discussion