top of page
Caută

Here's something that didn't make many headlines but probably should have

Poza scriitorului: Office Bucuresti
Office Bucuresti
28 sept.
2 min de citit

Actualizată în: acum 1 zi

Here's something that didn't make many headlines but probably should have

Japan just dismantled its first confirmed North Korean "laptop farm" — a house where someone was hosting laptops so remote operators on the other side of the world could control them and make it look like they were logging in locally. US and allied agencies say this is one piece of a bigger operation, tracked under names like WaterPlum or "Contagious Interview," that's reportedly been running since 2022.


The setup works two ways, and both start on LinkedIn.


One version: someone posing as a recruiter reaches out to a developer with a great-sounding job offer. Once there's some rapport, the "next step" is a coding test or technical assessment — and running that assessment is what actually installs the malware. From there, attackers get backdoor access, steal crypto wallet credentials, and in some cases work their way into the victim's employer's systems too.


The other version is more direct: the operative gets hired for an actual remote job using a stolen or fabricated identity. Their laptop gets shipped to an accomplice's house in the target country — the "farm" — who plugs it in and keeps it running so the employer sees what looks like a normal local login. Some of these operators reportedly hold down real day jobs doing legitimate development work while running the rest of the operation on the side.


Investigators are tying wallets from this campaign to North Korea's 313 General Bureau, under the Munitions Industry Department — so allegedly, this isn't just cybercrime, it's a funding channel. Agencies estimate at least 30,000 devices compromised across 100+ countries, and just over $10.7 million in crypto reportedly moved out.


If your team hires developers remotely, a few things reportedly stand out on the applicant side: heavy VPN use paired with a background story that doesn't quite add up, a resume listing every skill under the sun, English that doesn't match the claimed background, refusing any video call, insisting on crypto payment, or someone whose eyes keep drifting to a second screen during the interview.


None of these alone means much. Together, they're worth a second look before anyone gets handed systems access.


Sources: SecurityWeek, The Hacker News, Infosecurity Magazine


Originally published on the IPSTSO LinkedIn page on 28 September 2026: view the post

 
 
 

Comentarii


Nu se mai pot adăuga comentarii la această postare. Contactează proprietarul site-ului pentru mai multe informații.
bottom of page
Sigla IPSTSOIPSTSOINTERNATIONAL POLICE SECURITY TECHNOLOGY SYSTEM ORGANIZATIONDEPUNE O SESIZARE