North Korean-linked operators used fake job interviews to infect 30,000 devices
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 21st, 2026.
Developers and employers now face theft and network intrusion through recruitment processes that look routine. Authorities said North Korean-linked operators infected more than thirty thousand devices across 100+ countries between December 2025 and July 2026. The campaign obtained funds or account credentials from more than seven thousand cryptocurrency wallets and moved at least ten point seven dollars million in cryptocurrency to North Korea. Targets were approached with supposed jobs, contracts, or collaboration opportunities and then persuaded to run malicious coding projects or attacker-supplied commands. A compromised developer device can expose cloud credentials, source code, wallet keys, customer systems, and corporate accounts. Organizations also face the separate risk of remote workers seeking employment under stolen identities. Leaders should connect hiring security with developer security and create shared escalation paths. Defenders should isolate untrusted assessments, verify recruiter identities independently, limit contractor access, and revoke suspicious accounts and sessions quickly. Candidates and staff should run unsolicited coding assessments only in isolated environments that contain no corporate credentials.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.