North Korea now has at least two known hacking groups running fake-job scams against tech workers at the same time.
A newly tracked operation called UNK_DeadDrop has been caught luring hundreds of workers — developers in particular — with fraudulent job offers, then using that foothold to steal cryptocurrency and other data. The approach closely mirrors tactics long associated with Lazarus Group, North Korea's most prominent state-sponsored hacking unit, but security researchers are tracking UNK_DeadDrop as a separate entity. What the two groups share is a proven formula: manufacture a plausible job opportunity, get a target to run something they shouldn't, and walk away with credentials or funds.
The fact that a second distinct group is now running the same fake-job playbook suggests North Korea is treating this vector as a repeatable institution, not a one-off experiment. Developers are an especially attractive target because they tend to have access to internal systems, deployment pipelines, and personal crypto wallets — all in one place.
Fake job interviews as a phishing lure have been in active use for years. At this point, any unsolicited outreach offering a developer role at a crypto-adjacent company deserves a long pause before a single line of code gets cloned.
