The Jerusalem PostMoscow summons British envoy over weapons supplies to UkraineESPNSources: Jazz, George reach $157.5M extensionESPN DeportesBayern toma ventaja sobre Union BerlínRTP DesportoLiga das Nações. Sportinguista Doumbia chamado pela primeira vez à seleção italianaוואלהאישה פלסטינית הותקפה באזור חירבת מרכז; המשטרה פתחה בחקירהBillboardKarol G Dazzles at MetLife Stadium, Brings Tainy, Judeline & rusowsky for ‘BbY WOW’: 5 Best MomentsCollider6 Flawless Miniseries With No Weak Episodes, RankedABC News'Foreign actors' targeted small, private water providers in Colorado: GovernorInquirerHabagat returns, brings rains to parts of Luzon, VisayasANSAScoppia il caso Aspides, Roma chiede all'Ue più navi e fondiVarietyCanada’s BetterHalf Films Joins Indonesia’s Studio Amarana on Animated Film ‘Galeo of the Seawalkers’ (EXCLUSIVE)BBC NewsMcIlroy in mix heading into weekend at Wentworth
The Daily Newsstand · Free, Always
Friday, September 18, 2026

North Korea's fake job interviews infected 30,000 devices

Translate

WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets

North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory.

Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime.

The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches.

REG AD

During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware.

REG AD

Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends.

In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment.

WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation.

"Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion."

The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang.

The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies.

The scheme has been extensively documented and has generated revenue for North Korea for years.

Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired.

REG AD

The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state.

The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year.

The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates.

Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview.

Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency.

Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins.

The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.