North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs
- ID
- 26507
- Status
- summarized
- Published
- 20 Sep 2026, 8:10 PM
- Fetched
- 20 Sep 2026, 9:59 PM
- Provider
- Tom's Hardware
- Category
- technology
- Original URL
- https://www.tomshardware.com/tech-industry/cyber-security/north-korea-used-job-interviews-to-deploy-malware-on-30-000-devices-during-coding-tests-waterplum-group-loots-usd10-7-million-in-crypto-and-plants-persistent-rats
- Source URL
- https://www.tomshardware.com/feeds/all
Summary
- Score
- 6.5
- Created
- 20 Sep 2026, 9:59 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
North Korea's WaterPlum group used fake job interviews requiring coding tests to deploy malware on 30,000 devices, stealing $10.7 million in crypto and installing persistent remote access trojans. The attack vector targeted developers through what looked like legitimate technical assessments.
Why it matters
If you or your team participate in coding challenges or take-home tests from unfamiliar companies, run them in isolated VMs or sandboxes — not your primary dev machine. Founders hiring remote developers should also scrutinize any third-party coding-test platforms they send candidates to, as compromised interview tooling cuts both ways.
Discussion angle
How to safely handle coding tests and technical interviews from unknown companies — practical sandboxing setups that don't kill your workflow, and red flags to watch for in interview tooling.