North Korean Hackers Compromise 30,000 Devices via Fake Recruitment Scheme
Industry Pulse News Desk · 2026-09-20

Cybersecurity agencies warn that threat actors posed as recruiters to infect developers' devices with malware hidden in coding assignments and software fixes.
Global cybersecurity officials issued a joint advisory warning that a sophisticated cyber campaign linked to North Korean state-sponsored hackers has compromised more than 30,000 devices worldwide. The threat actors successfully infiltrated systems by posing as corporate recruiters targeting IT personnel and software developers.
According to security alerts, the deceptive scheme relies on fake job interviews and pre-employment technical assessments. Hackers tricked applicants into downloading malicious files disguised as standard coding tests or required performance fixes for popular video-conferencing software platforms.
Once executed on a developer's local machine, the malicious code grants attackers persistent remote access to the device. From these infected endpoints, threat actors moved laterally into broader corporate environments to harvest sensitive credentials, steal intellectual property, and access critical databases.
The multi-year operation has impacted organizations across various key sectors, including defense, aerospace, financial services, and telecommunications in dozens of countries. Investigators noted that the actors frequently used stolen identities and established fraudulent profiles on professional networking sites to build credibility.
Federal security agencies recommend that enterprise IT administrators implement strict application controls and perform additional identity verification for remote job candidates. Organizations were also advised to review system logs for indicators of compromise linked to unauthorized remote management tools and unexpected data exfiltration.