North Korea's fake job interviews infected 30,000 devices

Law enforcement and cybersecurity agencies from Australia, Germany, Japan and the US issued an updated advisory on Thursday about a North Korean campaign they track as WaterPlum, in which regime-backed operators pose as recruiters to infect jobseekers' devices rather than plant their own workers inside companies. The campaign has infected more than 30,000 devices and stolen over $10 million, and separately, the agencies said the attackers compromised more than 7,000 cryptocurrency wallets.
WaterPlum targets web designers, engineers, and cryptocurrency and Web3 specialists. During a supposed interview process, victims are told to download files presented as coding assignments or other recruitment tests; opening them backdoors the applicant's computer and installs malware. The attackers then deploy remote access trojans and information stealers, giving them persistent access to credentials, clipboard contents, keystrokes, cryptocurrency wallet data and identity documents long after the fake interview ends. In some cases, a compromised machine can later provide a route into corporate systems if the jobseeker goes on to land real employment.
"Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang; the article does not say whether that figure overlaps with, or adds to, the more than $10 million cited for the recruiter scheme specifically.
The recruiter campaign runs alongside North Korea's better documented tactic of placing its own IT workers directly in technology jobs at Western and allied companies, often via laptop farms that make remote workers appear to be based wherever they were hired. Researchers estimate roughly 100,000 North Korean IT workers are employed or seeking work worldwide, and the agencies believe the broader IT worker fraud nets Kim Jong Un's regime upwards of $500 million a year.
The advisory lists warning signs for employers: resumes claiming prestigious credentials that do not hold up under interview scrutiny, repeated refusals to meet in person, suspicious interruptions or voices during video calls, requests for payment in cryptocurrency, and cameras disabled shortly after a call starts, which can follow visual artifacts produced by AI face-swapping software used to disguise the applicant. Agencies recommend that any organization suspecting it hired a fraudulent North Korean IT worker launch a full forensic investigation and assume credentials and other sensitive data have already been compromised.
Key facts
- North Korea's WaterPlum campaign posed as recruiters to backdoor more than 30,000 devices and steal over $10 million by disguising malware as coding-test files
- The attackers compromised more than 7,000 cryptocurrency wallets; agencies in Australia, Germany, Japan and the US attributed at least $10.71 million in thefts to these tactics, funneled to Pyongyang
- The scheme targets web designers, engineers, and cryptocurrency and Web3 specialists, and installs remote access trojans and information stealers that can later open a route into a victim's employer
- It runs alongside North Korea's placement of roughly 100,000 IT workers worldwide, a broader fraud the regime is thought to net upwards of $500 million a year from
- Warning signs flagged by the advisory include refusal to meet in person, video-call glitches from AI face-swapping software, and requests for payment in cryptocurrency
Why it matters
This is not the familiar story of North Korea sneaking its own operatives into Western payrolls; it inverts the con, using the hiring process itself as a delivery mechanism for malware against ordinary jobseekers. A four-country advisory update, rather than a one-off warning, signals a campaign large enough and persistent enough that Australian, German, Japanese and US agencies felt the need to jointly refresh guidance on it, and the more than 30,000 infected devices and 7,000 compromised wallets show the social engineering is working at scale.
Who it affects
Directly, jobseekers in web design, engineering and cryptocurrency or Web3 roles, the disciplines WaterPlum recruiters target with bogus coding tests. Indirectly, the employers of anyone who falls for the con: a compromised laptop bought to a job interview can become a corporate entry point once its owner is hired somewhere real, and stolen credentials, clipboard data and identity documents can be reused for further impersonation or extortion against employers, clients or contracting parties.
How to use it
The advisory's guidance is aimed at organizations, not just individual applicants: any company that suspects it engaged a fraudulent North Korean IT worker should launch a full forensic investigation and assume credentials and other sensitive data are already compromised, rather than waiting for confirmation. For people interviewing, the practical takeaway is to treat unsolicited coding-test downloads with the same caution as any unknown executable, especially when the recruiter also shows the advisory's other red flags.
How solid is it
This is a joint advisory from law enforcement and cybersecurity agencies in four countries, an update to an already-tracked campaign rather than a first disclosure, which is a solid institutional basis for the figures. That said, the article does not name individual agencies (only the four countries), does not identify specific malware families beyond generic "remote access trojans and information stealers," and does not name any victim companies or individuals, so the numbers should be read as the advisory's own minimums rather than independently verified totals.
Risks and caveats
The article does not clarify whether the more than $10 million tied to the recruiter scheme and the at least $10.71 million in total attributed thefts are the same figure, overlapping, or additive; both should be treated as separate, unreconciled numbers rather than summed. No start date or duration is given for the WaterPlum campaign beyond it being an update issued on a Thursday, and no specific malware tool names are disclosed.
“Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency. Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion.”
— Joint advisory from Australian, German, Japanese and US agencies