North Korea's Fake Recruiters Have Infected 30,000 Devices and Counting
North Korea's workforce fraud runs in both directions. While the regime has spent years embedding fake IT workers inside Western companies, its cybercriminals have also been running the opposite con: posing as recruiters to lure job hunters into installing malware. A joint advisory from law enforcement and cybersecurity agencies in Australia, Germany, Japan, and the US puts the damage at more than 30,000 compromised devices, over 7,000 cryptocurrency wallets drained, and at least $10.71 million stolen.
The agencies track this activity under the collective name WaterPlum. Its targets are not random. The operation focuses on web designers, software engineers, and cryptocurrency or Web3 specialists, people likely to have access to valuable systems and assets.
The mechanics are straightforward but effective. Victims receive what looks like a legitimate recruitment approach, get invited through a hiring process, and are then asked to download files framed as coding tests or technical assessments. Opening them gives the attackers a backdoor. From there, remote access trojans and information stealers go to work, quietly harvesting credentials, keystrokes, clipboard contents, wallet data, and identity documents.
The access does not necessarily end when the fake interview does. If a compromised job seeker later lands a real role at a company, their already-infected machine becomes a potential entry point into their new employer's systems. That is not a side effect. It is part of the design.
Stolen identities serve a second purpose: North Korean IT workers use them to impersonate real people when applying for legitimate remote jobs, helping them clear background checks and appear credible. The advisory also notes that sensitive material collected during intrusions has been used for extortion.
This recruiter campaign sits alongside North Korea's longer-running IT worker placement scheme, which is estimated to employ or be actively seeking work for around 100,000 people globally. Many are supported by laptop farm operators who make it appear that remote workers are physically located in the country where they were hired. Salaries collected from sanctioned employers get funnelled back to Pyongyang. The whole operation is thought to generate upwards of $500 million a year for the Kim regime.
Employers are slowly getting better at spotting the red flags. Suspiciously polished CVs, reluctance to appear on camera, visual glitches consistent with AI face-swapping software, background voices during calls, and requests for cryptocurrency payment have all become known indicators. Still, with the volume of applicants the regime puts forward, some will always get through.
The agencies' guidance for any organisation that suspects it has hired a fraudulent North Korean worker is blunt: assume credentials and sensitive data are already gone, and start a full forensic investigation.