North Korean hackers target freelancers – what to do now

AI‑powered malware targeting freelancers: why it matters to you
If you earn a living by writing code, designing websites, or maintaining apps, a single compromised laptop can wipe out months of work, steal client data, and even empty your cryptocurrency wallet. A new campaign run by a North Korean‑backed group called WaterPlum (also known as Contagious Interview) is specifically targeting freelancers with fake job offers and interview tests that drop AI‑driven malware onto your device. The threat is real, the tactics are simple, and the damage can be costly. Below you’ll find exactly what to look out for and how to keep your business safe.
How AI‑driven malware is delivered to freelancers
Delivery chain
-
A tempting job posting – The attackers post attractive gigs on online freelance marketplaces, social media groups, or even direct messages. The roles often promise high pay for short‑term development work.
-
A “technical interview” test – To appear legitimate, they ask candidates to complete a coding assignment or troubleshoot a simulated error during a video call. The test usually involves downloading a small project or a package from a public code repository.
-
Malicious code delivery – The downloaded files are not ordinary examples. They contain hidden AI‑powered malware such as BeaverTail or OtterCandy that can:
- Install a Remote‑Access Trojan (RAT) – software that lets an attacker control your computer remotely.
- Steal saved passwords, browser cookies, and cryptocurrency wallet keys.
- Use the infected machine as a stepping stone to attack other systems.
-
Financial gain for the attackers – In the first few months of the campaign, the group stole over $10 million and compromised more than 30 000 devices worldwide.
The whole chain relies on one simple mistake: running code that you did not verify yourself.
Red flags you can spot right away
| Red flag | What it looks like | Why it matters |
|---|---|---|
| Unexpected download links | A recruiter asks you to “clone a repo” or “download a zip file” that is not hosted on the official project page. | Malware is often hidden in seemingly harmless packages. |
| Requests to run code on your own machine | “Please run this script on your laptop so we can see the output.” | Executing unknown scripts gives the attacker direct access. |
| Pressure to act quickly | “We need the test completed within an hour or the contract is withdrawn.” | Urgency discourages you from double‑checking the source. |
| Recruiter cannot provide verifiable company details | No corporate email, vague company name, or a personal social‑media profile only. | Legitimate employers usually have a traceable online presence. |
| Requests for admin or root privileges | “Open the file as administrator” or “grant me remote desktop access.” | Elevated permissions let malware install deeper system components. |
If any of these appear, pause and verify before proceeding.
Step‑by‑step protection checklist
-
Verify the recruiter
- Look for a corporate domain email (e.g.,
@company.com). - Search the company name online; a legitimate business will have a website, LinkedIn page, or phone number.
- If you’re unsure, ask for a reference or a video call with a known employee.
- Look for a corporate domain email (e.g.,
-
Never run code you didn’t write or audit
- Use a sandbox – an isolated environment (often a virtual machine) where you can run unknown code without it affecting your real system.
- Or a separate virtual machine – a software‑based computer that runs inside your actual computer, used for safe testing.
-
Check package integrity
- When a repository is mentioned, go directly to the official site (npmjs.com, GitHub.com) and verify the author’s profile and download count.
- Look for recent reviews or reports of malicious activity.
-
Keep software up to date
- Enable automatic updates for your operating system, IDE, and any third‑party tools.
- Out‑of‑date libraries are a common entry point for malware.
-
Enable two‑factor authentication (2FA)
- Protect email, cloud storage, and especially cryptocurrency wallets with 2FA (an extra security step, like a code sent to your phone).
-
Back up your work securely
- Use encrypted, off‑site backups (cloud storage with end‑to‑end encryption or an external drive stored in a safe location).
- Test your backups regularly to ensure you can restore them quickly.
-
Install reputable anti‑malware software
- Choose a solution that offers real‑time scanning, ransomware protection, and web‑shield features.
- Endpoint protection that detects malware using AI helps stop threats before they spread.
-
Report suspicious offers
- If you encounter a likely scam, inform the platform where you found the job and, where appropriate, the relevant security agency.
Following this checklist dramatically reduces the chance that a fake interview will turn into a security incident.
FAQ: protecting freelancers from AI‑powered malware
Q: I need work urgently. Is it safe to skip the verification steps?
A: Skipping verification may save a few minutes now, but a single infection can cost you weeks of work, lost client trust, and possibly thousands of euros. Even a quick Google search can reveal red flags before you download anything.
Q: I’m not a security expert. How can I tell if a package is malicious?
A: Look at the publisher’s reputation, the number of downloads, and recent comments. If the package is brand‑new, has few downloads, or the description contains spelling errors, treat it as suspicious. When in doubt, run it in a sandbox first.
Q: Do I need a separate computer just for interview tests?
A: It’s a good practice, especially if you frequently apply for remote gigs. A low‑cost laptop or a virtual machine isolates your main work environment from potential threats.
Keep your freelance business safe with IT Move NL
Freelancers often wear many hats—developer, marketer, accountant—so security can fall through the cracks. At IT Move NL we specialize in Security & Protection and Maintenance & Support for small businesses and independent professionals. Our services include:
- Endpoint protection that detects malware using AI
- Automated, encrypted backups stored off‑site
- 24/7 monitoring and rapid incident response
If you’d like a quick, free security health‑check, just drop us a line. We can help you with:
- AI‑driven endpoint protection
- Automated, encrypted backups
- 24/7 monitoring and support
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch

