North Korea-linked cybercriminals, tracked as WaterPlum, have infected over 30,000 devices and stolen more than $10 million by posing as job recruiters and tricking applicants into downloading malware disguised as coding tests or recruitment materials. Once installed, the malware gives attackers persistent access to credentials, cryptocurrency wallets, and sensitive data, with proceeds funnelled to the North Korean regime. This scheme complements North Korea's broader strategy of placing fraudulent IT workers inside Western companies, an operation estimated to generate over $500 million annually for Pyongyang.