< Back to all clusters
[INTERNATIONAL] · Germany, Japan, United States, Australia, Slovakia · 13 sources

started · updated

North Korea cyber group targets IT specialists via fake job offers

International security agencies, including those in Germany, Japan, the United States, and Australia, have issued warnings regarding a North Korean cyber campaign targeting IT professionals. The operation, known in the security community as ‘Contagious Interview,’ utilizes social engineering to manipulate job seekers.

Attackers pose as representatives from artificial intelligence or cryptocurrency companies, contacting software developers through social media, job platforms, and freelance marketplaces. During the fraudulent recruitment process, candidates are prompted to download files for tasks that contain malware. Once access is gained, the attackers steal sensitive data and cryptocurrency.

Reports indicate that the group, sometimes referred to as ‘Waterplum,’ has targeted more than 30,000 devices across more than 100 countries. In one instance, hackers stole at least 11 million dollars in cryptocurrency. The stolen funds are believed to be used to bypass international sanctions and finance North Korea’s weapons and ballistic missile programs.

Entities

Federal Intelligence Service · Federal Office for the Protection of the Constitution · Japan National Police Agency · North Korea · Waterplum

Claims

What the coverage asserts, and how many sources carry each claim.