A deceptive campaign masquerading as legitimate job interviews has infected more than 30,000 devices worldwide, according to a joint advisory from five international agencies. The "Contagious Interview" operation, linked to North Korean threat actors known as WaterPlum, specifically targets macOS systems by exploiting the trust inherent in the recruitment process.

Published on September 18, the advisory was issued by Japan's National Police Agency, the FBI, the U.S. Department of Defense Cyber Crime Center, and the intelligence agencies of Australia and Germany. It highlights a tactical shift where attackers weaponize standard professional interactions rather than technical exploits. For technology professionals in active international job markets, this represents a significant and evolving risk.

The attack begins on professional networking platforms, where victims are approached by apparent recruiters and invited to a remote interview or skills assessment. During the interaction, they are directed to download a custom application, presented as necessary video conferencing or testing software. This application is malware designed to establish persistent access, harvest credentials, and steal data from the infected machine.

The campaign's deliberate focus on macOS is a key strategic element. Researchers note that some users perceive Apple's ecosystem as inherently more secure, a perception attackers are actively exploiting. The malware strains involved are purpose-built to circumvent macOS security controls and operate undetected on compromised systems.

This method leverages a powerful psychological lever: the compliance and urgency job seekers feel when dealing with potential employers. The actors behind the campaign capitalize on this professional courtesy, lowering the victim's guard during a high-pressure interaction.

The coordinated international warning underscores the scale of the threat and its association with state-sponsored activity. It serves as a critical alert for both individuals and the organizations that employ them.

How to Protect Yourself

For Job Seekers: * Vet the Recruiter: Independently verify the recruiting agency, hiring manager, and company using official websites and trusted professional networks. Be skeptical of unsolicited contact. * Never Download from Chat Links: Do not install software from URLs shared in messaging apps or emails. Legitimate companies will direct you to verified portals or official app stores. * Question "Custom Assessment" Requests: Authentic skills tests are conducted through established platforms. Treat any instruction to install a unique, interview-specific application as a major red flag. * Use a Separate Device: If possible, conduct job searches and interviews from a personal computer not connected to your primary work network.

For Organisations: * Train Staff on This Specific Threat: Incorporate this social engineering tactic into security awareness training, particularly for hiring managers and HR teams. * Standardize Interview Communications: Establish and communicate official protocols, ensuring candidates know your organization will never request software installation during initial interview stages. * Deploy Advised Defenses: Integrate the specific indicators of compromise (IOCs) from the joint advisory into your security monitoring systems to identify potential breaches.

As the lines between professional norms and cyber-attack vectors continue to blur, the primary defenses remain vigilance and verification. The Contagious Interview campaign demonstrates that human trust, not software vulnerability, is often the targeted entry point.


據五個國際機構的聯合通告,一場偽裝成合法招聘面試的欺騙性行動已在全球感染超過三萬台設備。這項名為「傳染性面試」的行動,與被稱為WaterPlum的北韓威脅行為者有關,專門利用招聘流程中固有的信任來針對macOS系統。

這份於9月18日發佈的通告由日本警察廳、聯邦調查局、美國國防部網絡犯罪中心,以及澳洲和德國的情報機構共同發出。通告突顯了一種戰術轉變:攻擊者將標準專業互動武器化,而非利用技術漏洞。對於活躍於國際就業市場的科技專業人士而言,這代表着一種重大且不斷演變的風險。

攻擊始於專業網絡平台,受害者會被看似招聘人員的人士接觸,並受邀進行遠程面試或技能評估。在互動過程中,他們會被指示下載一個特製應用程式,該應用程式被呈現為必要的視像會議或測試軟件。這個應用程式實為惡意軟件,旨在建立持久訪問權限、竊取憑證並從受感染的設備中盜取資料。

該行動刻意針對macOS系統,是關鍵的戰略要素。研究人員指出,部分用戶認為蘋果的生態系統本質上更安全,攻擊者正積極利用這一觀念。相關的惡意軟件變體專為繞過macOS安全控制而設計,能在受感染的系統上隱蔽運作。

這種方法利用了一個強大的心理槓桿:求職者在與潛在僱主打交道時所感受到的服從性和緊迫感。行動背後的攻擊者利用這種專業禮儀,在高壓互動期間降低受害者的警惕性。

這次國際間的協調警告突顯了威脅的規模及其與國家資助活動的關聯。它對個人及其僱用機構都發出了關鍵的警示。

如何保護自己

給求職者: * 核實招聘人員: 通過官方網站和可信賴的專業人脈,獨立查證招聘機構、招聘經理及公司。對主動聯繫的邀約要保持懷疑。 * 切勿從聊天連結下載軟件: 不要安裝來自通訊應用程式或電郵中分享的網址的軟件。正規公司會指引你前往已驗證的門戶或官方應用程式商店。 * 質疑「特製評估」要求: 正式的技能測試通過既定平台進行。任何要求你安裝一個獨特的、面試專用應用程式的指示,都應視為重大危險訊號。 * 使用獨立設備: 若有可能,使用未連接至主要工作網絡的個人電腦進行求職和面試。

給機構: * 就這項特定威脅對員工進行培訓: 將這種社會工程學攻擊手法納入安全意識培訓,特別是針對招聘經理和人力資源團隊。 * 標準化面試溝通流程: 建立並傳達官方流程,確保應徵者知道你的機構絕不會在初步面試階段要求安裝軟件。 * 部署建議的防禦措施: 將聯合通告中提供的具體入侵指標(IOC)整合到你的安全監控系統中,以識別潛在的入侵。

隨着專業規範與網絡攻擊向量之間的界線持續模糊,主要的防禦措施仍然是警覺和核實。「傳染性面試」行動表明,被瞄準的切入點往往是人為信任,而非軟件漏洞。

新聞來源 / Original News Source