Wagemole

2023-11-21 • Paloalto NetworksHacking Employers and Seeking Employment: Two Job…

Wagemole is a campaign name Palo Alto Networks' Unit 42 introduced in November 2023, tracked internally as CL-STA-0241, for North Korea state-sponsored threat actors who seek unauthorized remote employment with organizations in the United States and elsewhere, attributing the activity with high confidence to North Korea. Unit 42 discovered Wagemole infrastructure while investigating a related campaign it named Contagious Interview, which infects software developers with malware called BeaverTail and InvisibleFerret during fake job interviews to steal data later reused to build fraudulent identities; Wagemole operators use this stolen and purchased personal data, together with forged passports and driver's licenses, AI-assisted interview study guides, and automated job-application tooling on freelance platforms, to pass background checks and secure remote technical roles, often paid through services like PayPal to obscure financial trails. Subsequent research ties Wagemole proceeds to funding North Korean weapons programs and to specific individuals, and documents the operation adapting its personas' claimed locations, malware obfuscation, and persistence techniques over time while continuing to target banking, financial-services, and information-technology organizations.

Related Actors

Related Reports in This Cluster

Top Authors

View Wagemole reports only

View Wagemole reports only