Authorities say North Korean-linked hackers use fake job offers and “recruiter” outreach to trick software and IT professionals into downloading malicious files, infecting about 30,000 devices across more than 100 countries. The activity runs from December 2025 through July 2026, according to a joint cybersecurity advisory issued by agencies in Japan, Australia, Germany, and the United States, including the FBI and the Defense Department’s Cyber Crime Center.
Across reporting, the lure targets job seekers through social media, online job platforms, gig-work and freelance sites. Some victims are told to complete “technical interviews,” coding assignments, or video-conferencing troubleshooting steps that lead to malicious downloads, sometimes hosted on developer collaboration platforms and code repositories. The malware can steal browser passwords, screenshots, files, and cryptocurrency-wallet data, and may also enable access to victims’ employers’ networks, potentially facilitating intellectual-property theft and cyberespionage.
In addition to device infections, the operation is described as compromising roughly 7,000 cryptocurrency wallets, with reports of more than $10 million transferred to North Korea. Inc. and Slashdot also note overlaps with schemes where North Korean actors conceal identity to obtain remote IT work, and mention possible extortion and impersonation using stolen information.