North Korea's Fake Job Interviews Have Infected 30,000 Devices
An international security advisory from Australia, Germany, Japan and the US has revealed details of a North Korean state-backed campaign known as WaterPlum, which targets jobseekers, particularly web designers, engineers, and cryptocurrency or Web3 specialists, with fake recruitment offers. Victims are told to download files disguised as coding tests or interview assignments, which secretly install backdoors and malware on their devices.
Once a device is compromised, the attackers deploy remote access trojans and information stealers that harvest credentials, keystrokes, clipboard data, cryptocurrency wallet information and identity documents. In some cases, the infected computers later become a foothold into legitimate employers' systems once the victim secures a real job. The advisory notes that stolen identity documents can even be used by North Korean IT workers to impersonate victims and generate income for the regime.
Authorities have linked this campaign to the compromise of more than 7,000 cryptocurrency wallets and at least $10.71 million in stolen funds, which are believed to support North Korea's government. This activity runs alongside North Korea's separate, well-documented practice of embedding its own IT workers in Western companies under false identities.