A new joint alert from multiple governments warns that North Korea-linked hackers are weaponizing “fake job interviews” to breach tech and Web3 communities. The group, known as WaterPlum (also called Contagious Interview), has reportedly infected at least 30,000 devices across 100+ countries between Dec 2025 and Jul 2026. The targets weren’t random users—they were web designers, engineers, and professionals tied to crypto, blockchain, and Web3. Investigators say the attackers stole funds and credentials from 7,000+ crypto wallets, reaching at least $10.71M, with assessments suggesting links to North Korea’s military R&D and related industrial systems. How it works: scammers impersonate AI, crypto, or NFT employers on social media, job boards, and freelancing platforms. During the interview, victims are pressured to download files, run “code tests,” or troubleshoot video-call software—then malicious payloads are delivered and executed. Behind the scenes, they also deploy tainted NPM packages and then install RATs for persistent access, credential theft, and lateral movement. If an interview asks you to install unknown tools or open weird files, treat it as an attack vector. Verify, verify, verify. #CyberSecurity #Web3Security #Phishing #NPM #ThreatIntel #RAT
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论