Security News

North Korea's Fake Job Interviews Have Infected 30,000 Devices

The Register · 19 Sept 2026
Key Takeaway Treat unsolicited recruitment offers with caution and never download or run 'coding test' files from unverified recruiters without scanning them or using an isolated environment.

An international security advisory from Australia, Germany, Japan and the US has revealed details of a North Korean state-backed campaign known as WaterPlum, which targets jobseekers, particularly web designers, engineers, and cryptocurrency or Web3 specialists, with fake recruitment offers. Victims are told to download files disguised as coding tests or interview assignments, which secretly install backdoors and malware on their devices.

Once a device is compromised, the attackers deploy remote access trojans and information stealers that harvest credentials, keystrokes, clipboard data, cryptocurrency wallet information and identity documents. In some cases, the infected computers later become a foothold into legitimate employers' systems once the victim secures a real job. The advisory notes that stolen identity documents can even be used by North Korean IT workers to impersonate victims and generate income for the regime.

Authorities have linked this campaign to the compromise of more than 7,000 cryptocurrency wallets and at least $10.71 million in stolen funds, which are believed to support North Korea's government. This activity runs alongside North Korea's separate, well-documented practice of embedding its own IT workers in Western companies under false identities.

North Korea malware job scam cryptocurrency theft cybersecurity advisory

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.