Urgent.News

What's breaking now, across thousands of outlets.

Tech

North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs

Multiple government agencies across the world released a warning that North Korean hackers are posting fake jobs to install malware on unsuspecting applicants' computers. They then steal credentials and cryptocurrency from their victims, with over $10 million reported stolen.

North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs

Japanese, U.S., Australian, and German security agencies have warned of a North Korean cyber threat group known as "WaterPlum." This group has been deploying malware on the devices of job applicants through fraudulent job postings, stealing their credentials and cryptocurrency holdings. Over 30,000 devices across 100 countries have been infected, and more than 7,000 cryptocurrency wallets have been compromised, resulting in losses of $10.71 million.

The stolen cryptocurrency is believed to be funneled to the North Korean government, which uses fake IT personnel at legitimate companies to generate $500 million annually. The WaterPlum group also steals credentials and personal data, using them to apply for openings at Western companies. Amazon has blocked over 1,800 suspected North Korean applications since April 2024.

The attacks involve fake recruiters giving applicants coding assignments to evaluate their skills, which often contain hidden malware. This allows the attackers to maintain access to the victim's computer even after they secure a legitimate job, potentially enabling further attacks on their future clients. The fake recruiters typically target software developers and IT professionals with enticing job openings, using the names of legitimate AI, cryptocurrency, and NFT companies on various online platforms.

To protect themselves, potential applicants should apply directly with companies and on legitimate platforms, confirm the legitimacy of job openings by contacting the company directly, and set up an isolated virtual machine for interviews to minimize the risk of infection.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at tomshardware.com →

More in Tech

Extended Support Isn't Extended Security: Managing Vulnerabilities in ELS Linux Environments

You have a Linux server. It is running an enterprise operating system. The operating system is still under vendor support. Your vulnerability scanner reports 37 vulnerabilities .

  • Extended Support does not guarantee automatic vulnerability fixes
  • ELS Vulnerability Paradox: older systems face higher vulnerability risks
  • Validation process recommended for ELS vulnerability management

More from Sunday 20 September →