Helpnetsecurity North Korean Hackers Target Rust Developers with Job Scam
Article Content
- •North Korean hackers are targeting Rust developers via job interview scams.
- •Over 30,000 devices have been infected globally, with significant credential theft.
- •Developers are urged to verify new contacts and be cautious of unsolicited job offers.
North Korean threat actors are conducting a social engineering campaign targeting members of the Rust Project and popular crate maintainers. The attackers lure victims into video calls under the pretense of job offers or collaborations, convincing them to install malicious software or execute harmful commands. This tactic has been linked to previous incidents, including a compromise of the arrayref crate in August 2026. The Rust team reported that over 30,000 devices have been infected globally, with more than 7,000 cryptocurrency wallets compromised between December 2025 and July 2026. The attackers create convincing company profiles to pass initial scrutiny and use various tricks to persuade targets into compromising their devices. Authorities have warned that stolen credentials may be used for extortion or to exfiltrate sensitive information. Developers are advised to be cautious of unsolicited job offers and to verify the legitimacy of new contacts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track WaterPlum and Rust Foundation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
North Korean Operators Target Developers with OtterCookie Malware on macOS A malware campaign identified by Jamf Threat Labs targets macOS developers using trojanized disk images and installer packages to deliver OtterCookie malware. The attackers, linked to North Korea, utilize fake job interview lures to trick victims into executing malicious code. The campaign involves a multi-stage…