ASD Warns of North Korean Recruiters Targeting IT Professionals with Fake Job Offers
The Australian Signals Directorate (ASD) has joined intelligence agencies in Japan, Germany and the United States in warning that North Korean cyber actors are now posing as recruiters to target IT professionals worldwide. This reverses an earlier tactic in which North Korean IT workers sought employment in Western countries for purposes including cryptocurrency theft, spying and sabotage.
The joint advisory describes a threat actor known as WaterPlum, also called Contagious Interview, which lures IT professionals with fake job opportunities, sometimes posing as AI, cryptocurrency or NFT companies operating through recruitment services. Once a target engages with the fake hiring process, the actors attempt to install malware on their device to harvest sensitive information and steal cryptocurrency. WaterPlum is reported to have infected more than 30,000 devices across over 100 countries, draining more than 7,000 cryptocurrency wallets and transferring roughly $15.4 million to North Korea.
ASD would not confirm whether any Australian individuals or organisations have been affected, but said the tactics described are being used against organisations globally and encouraged Australian businesses to review the advisory to manage the risk of infiltration, data theft and cryptocurrency loss.