North Korean Hackers Target US AI and Crypto Job Applicants Through Fake Listings
North Korean hackers have shifted tactics, now targeting job applicants in the AI and cryptocurrency sectors through fake job platforms. Dubbed 'Contagious Interview' by security firm Validin, the operation aims to gain long-term access to candidates' systems before they join companies, rather than impersonating employees post-hire.
The scheme leverages the trust of job seekers, who are lured into completing seemingly legitimate interview tasks—such as coding tests or webcam setup prompts—that secretly compromise their devices. Validin CEO Kenneth Kinion emphasized the psychological advantage: candidates are more likely to engage with malicious files when believing they're part of a genuine hiring process.
This evolution in cyber-espionage highlights growing threats to tech talent pipelines, particularly in blockchain and AI development. The Kim Jong Un regime appears to be weaponizing recruitment channels to steal intellectual property and infiltrate organizations at the earliest possible stage.