
21.7K
Downloads
89
Episodes
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast every Tuesday at 6:30 a.m. ET, and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity professional or an executive looking to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you stay informed and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!
Join us monthly for an interactive Cyberside Chats: Live!
Youtube channel: https://www.youtube.com/LMGsecurity
Register Here: https://lmgsecurity.zoom.us/webinar/register/WN_4FpdxB0VQo6aURK1p7_k_g
Episodes

2 days ago
2 days ago
14 min
This week, Sherri and Matt dig into a joint advisory from seven government agencies across Japan, the US, Australia, and Germany naming WaterPlum, the North Korean actors posing as prospective employers to target software developers and IT professionals.
Japan’s National Police Agency reports at least 30,000 infected devices in more than 100 countries between December 2025 and July 2026, with funds or credentials taken from more than 7,000 cryptocurrency wallets and roughly $10.71 million moved to North Korea. Sherri and Matt break down how the lure works, why coding challenges are such an effective delivery mechanism, and what changed with the newest malware family, StoatWaffle, which can execute when a trusted folder is opened in VS Code. They connect it to the case LMG’s Tom Pohl analyzed in June and examine how North Korea is now working both sides of the hiring table, as both interviewer and applicant.
Key Takeaways:
- Make onboarding a security checkpoint. Identity verification should be an HR and IT project. Verify every new hire’s identity, issue fresh credentials, and monitor accounts closely during the first few weeks. A compromised candidate can bring an existing infection into your organization on day one. Because the same operation also uses fake applicants, verify claimed locations, IP addresses, and résumé skills.
- Treat password reuse as a policy issue, not a question. The malware Tom analyzed harvested saved credentials from ten different browsers. Require unique corporate passwords, audit them against known-breach lists, and use phishing-resistant MFA. Anyone with source code or administrative access should be considered for hardware-based authentication such as a YubiKey.
- Keep developers off personal devices. Personal laptops often combine job hunting, coding challenges, credentials, and crypto wallets. In one case Tom analyzed, the person infected wasn't even the primary laptop user. Require company-managed devices for anyone accessing code, cloud infrastructure, or production systems. If personal-device use is allowed, document it as an accepted risk.
- Extend security requirements to vendors and contractors. Your organization can be compromised through someone else's developer. Bybit lost roughly $1.5 billion after a developer at its wallet vendor was compromised. Ask vendors: Do developers use managed devices? How are they trained on fake-recruiter and malicious-package attacks? How do they prevent password reuse? How do they vet employees and subcontractors?
- Keep developer training current. Tom's case was identified because someone recognized the fake-interview pattern and reported it instead of running the code. These actors continuously evolve their methods. StoatWaffle is a good example: the risk has moved beyond "don't run code from strangers" to situations where simply opening a trusted folder can trigger execution. Make current threat briefings part of ongoing training for developers, IT staff, and contractors. Hiring has become an attack surface in both directions, and most security programs don't own either end of it.
References:
- Joint NPA/NCO/FBI/DC3/ASD’s ACSC/BND/BfV advisory on North Korean WaterPlum, Sept. 18, 2026: https://www.ic3.gov/CSA/2026/260918.pdf
- LMG Security, Anatomy of a Job Interview Supply Chain Attack (June 2026)
- Cyberside Chats, Damaged Goods: When Your New Hire Is Already Compromised (June 9, 2026): https://www.chatcyberside.com/e/damaged-goods-when-your-new-hire-is-already-compromised/
- NTT Security, OtterCookie analysis (Jan. 16, 2025): https://jp.security.ntt/insights_resources/tech_blog/en-contagious-interview-ottercookie/
- The Hacker News, North Korean hackers abuse VS Code auto-run tasks to deploy StoatWaffle (March 2026): https://thehackernews.com/2026/03/north-korean-hackers-abuse-vs-code-auto.html
- Microsoft Security Blog, Contagious Interview malware delivered through fake developer job interviews (March 11, 2026): https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/
- KnowBe4, How a North Korean Fake IT Worker Tried to Infiltrate Us (July 23, 2024; updated Oct. 19, 2024): https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us
- LMG Security, North Korea’s Deepfake Remote Workers (Aug. 13, 2025): https://www.lmgsecurity.com/north-koreas-deepfake-remote-workers-how-theyre-getting-inside-u-s-companies-and-how-to-stop-them/
- Cyberside Chats, Unmasking the North Korean Cyber Threat (Aug. 12, 2025): https://www.chatcyberside.com/e/unmasking-the-north-korean-cyber-threat/
- The Hacker News, Safe{Wallet} confirms North Korean attack on Bybit (March 2025): https://thehackernews.com/2025/03/safewallet-confirms-north-korean.html
- Infosecurity Magazine, coverage of the WaterPlum advisory.
2 days ago
14 min

No comments yet. Be the first to say something!