{
  "id": 8855584,
  "title": "North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide",
  "url": "https://urgent.news/2026/09/21/north-korean-hackers-posed-as-recruiters-they-infected-30-000-devices",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T05:34:00.000Z",
  "source": {
    "name": "Slashdot",
    "slug": "slashdot",
    "url": "https://yro.slashdot.org/story/26/09/20/2349221/north-korean-hackers-posed-as-recruiters-they-infected-30000-devices-worldwide"
  },
  "original_language": "en",
  "account": "North Korean hackers employed deceptive recruitment tactics to infiltrate the devices of over 30,000 individuals in more than 100 countries, resulting in the compromise of 7,000 cryptocurrency wallets and the transfer of over $10 million (USD) to North Korea. This hacking campaign transpired from December 2025 to July 2026, as detailed in a joint cybersecurity advisory released by Japanese, Australian, German, and U.S. authorities, including the FBI and the Defense Department's Cyber Crime Center.\n\nThe suspects have been operating since 2023, engaging in both financial crimes and cyber espionage. Their primary method of attack is through social media, online job platforms, gig-work sites, and freelance marketplaces. The perpetrators pose as recruiters, asking potential victims to partake in virtual interviews or solve coding challenges. Subsequently, the attackers instruct their targets to download and run malicious files, often disguised as assignments or video conferencing assistance.\n\nOnce the group infiltrates a device or network, it employs malware to pilfer information such as browser passwords, screenshots, files, and cryptocurrency-wallet data. Infected computers can also serve as gateways into the networks of the victims' employers, facilitating intellectual property theft and espionage.\n\nThis operation is linked to another scheme where North Korean nationals use false identities and locations to secure remote IT jobs abroad. The malicious files are hosted on various online collaboration software developer platforms and code repositories, including malicious Node Package Manager (NPM) packages.\n\nThe perpetrators also steal ID images to impersonate victims and secure contracts, often demanding payment in cryptocurrency sent to an account in another person's name. During interviews, they sometimes use face-swapping software to claim network issues and disable their video. During North Korean holidays, the actors engage in leisure activities instead of carrying out their malicious activities.",
  "summary": "\"I would like to verify your technical abilities, so please download the specified file and complete the assigned task...\" Fake job listings aimed at software developers and IT professionals led to 30,000 infected devices in over 100 countries — and 7,000 compromised cryptocurrency wallets, leading to over $10 million (USD) transferred to North Korea. Inc. reports: The hacks occurred from…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}