← BACK TO FEED
North Koreacybercrimemalwarecrypto theftrecruitment scams

North Korea's Fake Recruiters Have Infected 30,000 Devices and Counting

North Korea-linked cybercriminals, tracked as WaterPlum, have infected over 30,000 devices and stolen more than $10 million by posing as job recruiters and tricking applicants into downloading malware disguised as coding tests or recruitment materials. Once installed, the malware gives attackers persistent access to credentials, cryptocurrency wallets, and sensitive data, with proceeds funnelled to the North Korean regime. This scheme complements North Korea's broader strategy of placing fraudulent IT workers inside Western companies, an operation estimated to generate over $500 million annually for Pyongyang.

North Korea's workforce fraud runs in both directions. While the regime has spent years embedding fake IT workers inside Western companies, its cybercriminals have also been running the opposite con: posing as recruiters to lure job hunters into installing malware. A joint advisory from law enforcement and cybersecurity agencies in Australia, Germany, Japan, and the US puts the damage at more than 30,000 compromised devices, over 7,000 cryptocurrency wallets drained, and at least $10.71 million stolen.

The agencies track this activity under the collective name WaterPlum. Its targets are not random. The operation focuses on web designers, software engineers, and cryptocurrency or Web3 specialists, people likely to have access to valuable systems and assets.

The mechanics are straightforward but effective. Victims receive what looks like a legitimate recruitment approach, get invited through a hiring process, and are then asked to download files framed as coding tests or technical assessments. Opening them gives the attackers a backdoor. From there, remote access trojans and information stealers go to work, quietly harvesting credentials, keystrokes, clipboard contents, wallet data, and identity documents.

The access does not necessarily end when the fake interview does. If a compromised job seeker later lands a real role at a company, their already-infected machine becomes a potential entry point into their new employer's systems. That is not a side effect. It is part of the design.

Stolen identities serve a second purpose: North Korean IT workers use them to impersonate real people when applying for legitimate remote jobs, helping them clear background checks and appear credible. The advisory also notes that sensitive material collected during intrusions has been used for extortion.

This recruiter campaign sits alongside North Korea's longer-running IT worker placement scheme, which is estimated to employ or be actively seeking work for around 100,000 people globally. Many are supported by laptop farm operators who make it appear that remote workers are physically located in the country where they were hired. Salaries collected from sanctioned employers get funnelled back to Pyongyang. The whole operation is thought to generate upwards of $500 million a year for the Kim regime.

Employers are slowly getting better at spotting the red flags. Suspiciously polished CVs, reluctance to appear on camera, visual glitches consistent with AI face-swapping software, background voices during calls, and requests for cryptocurrency payment have all become known indicators. Still, with the volume of applicants the regime puts forward, some will always get through.

The agencies' guidance for any organisation that suspects it has hired a fraudulent North Korean worker is blunt: assume credentials and sensitive data are already gone, and start a full forensic investigation.

READ NEXT
Russian Hacker Extradited Over Excel Macro Campaign That Hit 80,000 Freelance Platform UsersMeet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing FirstNorth Korean Hackers Are Quietly Poisoning Open Source Repositories