WaterPlum's Fake Interviews Hit 30,000 Devices
A joint advisory says North Korean recruiters posed as hiring managers, using bogus coding tests to breach 30,000 devices and 7,000 crypto wallets.
North Korea's employment scams have typically run in one direction: regime-linked workers quietly filling IT roles at Western companies. A joint advisory issued Thursday describes the same infrastructure being pointed the other way, with operatives posing as recruiters to compromise the machines of jobseekers themselves. The campaign, tracked as WaterPlum, has infected more than 30,000 devices and pulled in more than $10 million, according to the advisory.
Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US published the update, which states that the operators compromised more than 7,000 cryptocurrency wallets and routed the proceeds to support the North Korean regime. The advisory attributes at least $10.71 million in thefts to the tactics. The targets are web designers, engineers, and cryptocurrency and Web3 specialists — people whose work touches codebases, credentials, and wallet keys.
How the fake interviews work
The mechanics, as described in the advisory, begin with a recruitment approach. During a supposed interview process, the operators instruct victims to download files labeled as coding assignments or other recruitment tests. Opening those files backdoors the applicant's computer and installs malware.
From that initial foothold, the attackers deploy remote access trojans and information stealers. The advisory says this gives them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment.
The advisory does not describe a technical exploit that bypasses a fully patched system; it describes files that victims are persuaded to open. That distinction matters for defenders parsing the report: the initial access depends on the target running a recruiter's file, not on a software flaw.
What the operators take
Once inside, WaterPlum operators use their access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation.
Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency. Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion.
— the joint advisory from Australia, Germany, Japan, and the US
The wallet data sits at the center of the financial toll. The advisory states the operators compromised more than 7,000 cryptocurrency wallets, with funds ultimately supporting the North Korean regime.
The numbers behind the campaign
- More than 30,000 devices infected by the campaign
- More than 7,000 cryptocurrency wallets compromised
- At least $10.71 million in thefts attributed to these tactics
- $500 million a year thought to be generated by North Korea's broader IT worker fraud
- Roughly 100,000 North Korean IT workers estimated to be employed or seeking work worldwide
The worker-placement side of the scam
The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The advisory describes that scheme as extensively documented and generating revenue for North Korea for years.
Some of those workers are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year.
Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. The scale of the operation means some applicants inevitably succeed, even as employers grow more familiar with the signs of fraudulent North Korean candidates — an awareness the advisory connects to the broader effort to spot such hires.
Signs of a fraudulent candidate
The advisory lists warning signs that have surfaced as employers gain exposure to the practice. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview.
Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins.
Those tells sit alongside the recruiter-facing version of the scam, where the suspicious download request arrives early and is framed as a routine part of the hiring process.
Why the recruiter tactic lands
The advisory's account shows a straightforward asymmetry: the attackers need a single successful download, while the jobseeker needs to weigh a plausible request from someone who appears to be a hiring manager. The advisory documents no specific targeting rationale beyond the professional categories it lists — web designers, engineers, and cryptocurrency and Web3 specialists.
The campaign's reported reach suggests that job-seeking professionals in those fields are encountering the approach at scale. The advisory's figures place the device and wallet counts in the tens of thousands, and the confirmed thefts above $10 million, with the proceeds described as supporting the North Korean regime.
What the advisory tells organizations to do
The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised.
That guidance applies to the employer side of the ledger. For the jobseeker who ran a recruiter's coding test, the advisory's mechanics describe a compromised machine holding credentials, wallet data, and identity documents — material the advisory says can be reused for impersonation, exfiltration, and extortion.
The advisory does not detail remediation steps for individual applicants, and it does not name specific victim companies or individuals. It frames the response around organizations that may have hired or considered a fraudulent worker, and around the assumption that compromise has already occurred.
A two-way employment pipeline
Read together, the advisory describes North Korea's employment-related operations as working in both directions. One lane places regime-linked workers inside companies; the other uses fake recruiters to break into the people applying for jobs. Both are tied to the same financial objective, and the advisory puts the broader worker-placement fraud at upwards of $500 million a year.
The recruiter campaign's reported totals — more than 30,000 infected devices, more than 7,000 compromised wallets, and at least $10.71 million in attributed thefts — sit alongside an estimated 100,000 North Korean IT workers employed or seeking work worldwide. The advisory's warning signs, from refusal to meet in person to requests for cryptocurrency payment to abrupt camera shutdowns, are presented as indicators employers can use to spot the placement side of the operation.
What this means for defenders
The practical consequence for hiring organizations is that a recruitment pipeline can double as an intrusion vector in both directions. A candidate who completes a coding assignment from a fraudulent recruiter may later be hired by a legitimate employer, carrying a compromised machine — and its persistent access — into that environment. The advisory's recommendation to assume credentials and sensitive data were compromised, and to run a full forensic investigation, reflects that possibility.
For individual technologists, the advisory's mechanics suggest caution around unsolicited recruitment contacts that arrive with downloadable files, whether framed as tests, assignments, or onboarding paperwork. The reported totals indicate the approach has been attempted widely enough to reach tens of thousands of devices, and the operators' stated interest in wallet data, credentials, and identity documents means the payoff extends well beyond a single machine.
This suggests that as long as North Korea's IT worker operations generate revenue — the advisory puts the broader fraud at upwards of $500 million a year — the recruiter-facing variant is likely to remain in circulation. Employers and jobseekers alike are operating in the same market the operators are mining, which is what gives the fake-interview tactic its reach.
Sources
- The Register Original source
Continue Reading
Fake Cop Scams Cost Victims $1.6B
FBI's IC3 logged nearly 61,000 impersonation complaints from January 2025 to July 2026, with average losses exceeding $26,000.
Plugin4Shell Exposes AI Coding Agents to RCE
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
Settra Ransomware Hits Retail and Manufacturing
Huntress details a new ransomware variant that sabotages recovery options and deploys BYOVD in retail and manufacturing attacks.