< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [INTERNATIONAL]

2 clusters · 19 sources · 6 days · First seen · Last updated

North Korean cyber recruitment fraud

Overview

North Korean cyber operatives are utilizing fraudulent recruitment tactics to infiltrate foreign companies and bypass international sanctions. Initial reports indicate a sophisticated method where North Korean teams use third-country nationals from nations including Iran, South Africa, Nigeria, Lebanon, and India to act as proxy interviewers. These facilitators participate in video interviews and coding tests to evade detection, such as AI deepfake filters, before handing technical work to North Korean operatives. A US-led assessment estimated these disguised IT employment schemes earned North Korea up to $800 million in 2024, funds believed to finance weapons development.

Following these developments, intelligence agencies in Germany, Japan, the United States, and Australia issued a joint warning regarding a specific campaign dubbed ‘Contagious Interview’. This campaign, attributed to the ‘Waterplum’ group, involves state-sponsored actors using social engineering on social media and freelance marketplaces. By posing as representatives from AI or cryptocurrency firms, attackers guide candidates to download malicious files during fraudulent interviews. These files facilitate the theft of sensitive data and cryptocurrency, which is reportedly used to fund North Korea’s sanctioned programs.

Recent data indicates the scale of the ‘Contagious Interview’ operation has expanded significantly, with reports suggesting the group has targeted more than 30,000 devices across more than 100 countries. In at least one documented instance, hackers successfully stole 11 million dollars in cryptocurrency. These stolen assets are believed to be used to bypass international sanctions and finance North Korea’s ballistic missile and weapons programs.

Entities

North Korea · DTEX · Federal Intelligence Service · United States · U.S. Department of State

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. about 6 hours ago

    [INTERNATIONAL] 13 sources
    North Korea cyber group targets IT specialists via fake job offers

    Security agencies warn of a North Korean cyber campaign, ‘Contagious Interview,’ targeting IT specialists via fake job offers to steal cryptocurrency and fund weapons programs.

  2. 6 days ago

    [TECHNOLOGY] 6 sources
    North Korea uses third-country proxies to bypass IT job interviews

    North Korea is using IT workers from third countries like Iran and Nigeria to act as proxies in job interviews to infiltrate Western companies and fund weapons programs.

Sources

africa.businessinsider.com · allgaeuer-zeitung.de · bbv-net.de · bitcoinethereumnews.com · blog.coincodecap.com · dattelner-morgenpost.de · dorstenerzeitung.de · halternerzeitung.de · hnonline.sk · ibtimes.co.uk · kyeonggi.com · leinetal24.de · n-tv.de · ruhrnachrichten.de · stimberg-zeitung.de · tokenpost.kr · vosveteit.zoznam.sk · waltroper-zeitung.de · wz.de

This summary has been updated 1 time: see revision history