Fake Job Offers, Real Theft: North Korean Hackers Target IT Job Seekers Worldwide
Security agencies from the US, Japan, Australia and Germany have jointly warned about a North Korean hacking operation known as WaterPlum, also called Contagious Interview, which poses as employers to target software developers and IT professionals. The group impersonates legitimate AI, cryptocurrency and NFT companies, sometimes using recruitment services, to lure victims into compromising their own devices during fake hiring processes.
According to the alert, WaterPlum has infected more than 30,000 devices across over 100 countries, with victims concentrated in Japan, the United States and Europe. The group has stolen the equivalent of nearly $11 million in cryptocurrency from more than 7,000 crypto wallets. Investigators found significant overlap between WaterPlum and known North Korean IT worker schemes, including shared IP addresses used to access device farms and apply for jobs at a Japanese cryptocurrency exchange.
The agencies say they have had some success disrupting the group's activity but are calling for greater international cooperation. They have released technical details on WaterPlum's tactics to help organisations identify and defend against this threat.