North Korea’s Job Interview Scam: Two-Way Fraud Exposed

www.news4hackers.com-north-korea-s-job-interview-scam-two-way-fraud-exposed-north-korea-s-job-interview-scam-two-way-fraud-exposed

The warning was issued last week by the Rust Project s crates.io team and security response working group, highlighting a recurring pattern: a target receives an invitation to a video call framed as a job, contract, or collaboration opportunity, then is encouraged to install software or execute an attacker-supplied command.

Meet Contagious Interview (aka WaterPlum)

Rust developers are not the only victims of this approach: other software developers, package maintainers, web developers, IT professionals, and job seekers are also at risk. The tactics have been employed by North Korean state-sponsored actors for years. International authorities reported that between December 2025 and July 2026, the threat group infected over 30,000 devices across 100+ countries and stole funds or account credentials from more than 7,000 cryptocurrency wallets. Investigators also found that Contagious Interview s hackers and North Korean IT worker operations share infrastructure and personnel.

From cold message to compromise

Contagious Interview attackers focus on individuals, often posing as recruiters from plausible AI, blockchain, or NFT firms. Their methods include: Contacting targets via social media or online job platforms. Convincing victims to participate in online interviews or collaboration calls, often with coding components. Using technical difficulties or interview requirements to persuade targets to run malicious code, install malware, or enter credentials into spoofed pages. Stolen credentials may be used to exfiltrate crypto assets, personal data, trade secrets, or other sensitive information from victims employers, clients, or partners. Attackers can also leverage stolen data for extortion, as warned by Japanese, U.S., Australian, and German authorities. Stolen identities also support North Korea s IT worker scheme, enabling salaries to be funneled back to the sanctioned regime. DPRK IT workers use stolen identities to secure remote roles, applying for jobs with real accounts of impersonated individuals while proxies simulate their presence during interviews. Laptop farms help maintain the illusion of geographic location for these operatives.

What developers can do

The most effective defense is controlling initial contact protocols. The Rust advisory urges maintainers to be cautious of unsolicited outreach and to initiate calls rather than accepting links from unknown sources. Additional recommendations include: Conducting thorough independent verification of recruiters and companies. Treating any request to install software or execute commands as a critical red flag, regardless of how routine it sounds (e.g., “install this codec,” “run this to fix your setup”). Executing take-home assignments or unfamiliar code only in isolated virtual machines or sandboxes, never on devices storing credentials, keys, or signing materials. Avoiding execution of scripts without full understanding of their purpose. Opening unknown VSCode projects only in Restricted Mode. Harvey also advised developers to enable multi-factor authentication and review account activity on platforms that provide this visibility. Affected individuals should contact the Crates.io team or Rust Project security team for assistance.

What companies can do

Organizations face dual threats: compromised developers and exploited hiring processes that enable North Korean IT workers to gain employment. The international authorities advisory addresses both risks. On the technical side, it recommends deploying Endpoint Detection and Response (EDR) tools to detect and block malicious activity, extending the above-mentioned precautions about VSCode and untrusted code to corporate devices. For hiring, the advisory outlines screening measures based on a Japanese exchange case where a suspected operative was rejected: Monitor for sudden surges of applications for low-volume roles. Verify that an applicant s IP address aligns with their claimed location. Confirm contact details and certifications. During interviews, ask candidates to elaborate on skills listed on their resumes and inquire about personal details like hometown, local weather, or hobbies that are difficult for impersonators to answer. Treat cryptocurrency payments or requests to route compensation through third-party accounts as warning signs. Watch for reluctance to meet in person, repeated audio/video disruptions, background noises, or frequent glances at secondary screens. Attackers have used AI face-swapping techniques, then terminated video calls citing connectivity issues. Once inside, the advisory emphasizes limiting access to source code, credentials, and systems to the minimum necessary. If a contractor or subcontractor is suspected of being a North Korean IT worker, revoke their accounts and sessions immediately and notify law enforcement (as knowingly compensating these individuals may violate sanctions).

See also:

  • North Korean remote workers are broadening their job hunt beyond IT
  • How well do you know your remote IT worker?
  • More about account hijacking
  • cryptocurrency cyber espionage
  • enterprise government-backed attacks
  • North Korea remote working
  • Rust scams
  • Social engineering
  • software development tips



About Author

en_USEnglish