The record
Written from the 1 report below. Nothing here is unsourced.
- Threat actors linked to North Korea are targeting IT professionals with fake job offers on social media platforms like LinkedIn.
- Victims are prompted to complete coding tests that install malware, leading to credential theft and financial losses.
- The campaign has compromised 30,000 devices across more than 100 countries.
- Attackers leverage these access points to steal cryptocurrency and conduct corporate espionage.
What to watch next
- Identification and dismantling of additional laptop farms used for remote device management.
- Expansion of proxy hiring schemes on communication platforms like Discord.
- Continued use of AI-generated identities by North Korean IT workers.
Coverage1
1 report
English national1
All filed from India
Named Japan · United States · Australia · Germany · 313 General Bureau of the Munitions Industry Department · DTEX · Kudelski Security · North Korea · Palo Alto Networks Unit 42 · Sekoia · Silent Push
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
