Security News

Fake Job Offers, Real Theft: North Korean Hackers Target IT Job Seekers Worldwide

CyberScoop · 19 Sept 2026
Key Takeaway Australian businesses hiring remote IT or crypto talent should verify recruiters independently and avoid running unfamiliar software or scripts as part of any 'job interview' process.

Security agencies from the US, Japan, Australia and Germany have jointly warned about a North Korean hacking operation known as WaterPlum, also called Contagious Interview, which poses as employers to target software developers and IT professionals. The group impersonates legitimate AI, cryptocurrency and NFT companies, sometimes using recruitment services, to lure victims into compromising their own devices during fake hiring processes.

According to the alert, WaterPlum has infected more than 30,000 devices across over 100 countries, with victims concentrated in Japan, the United States and Europe. The group has stolen the equivalent of nearly $11 million in cryptocurrency from more than 7,000 crypto wallets. Investigators found significant overlap between WaterPlum and known North Korean IT worker schemes, including shared IP addresses used to access device farms and apply for jobs at a Japanese cryptocurrency exchange.

The agencies say they have had some success disrupting the group's activity but are calling for greater international cooperation. They have released technical details on WaterPlum's tactics to help organisations identify and defend against this threat.

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.