North Korea’s fake job interviews infected 30,000 devices
North Korean cybercriminals posing as recruiters used fake coding tests and job interviews to infect more than 30,000 devices and steal over $10 million. The WaterPlum campaign targeted web designers, engineers and cryptocurrency specialists, potentially giving attackers access to victims’ future employers and enabling theft of intellectual property, credentials and digital assets.
An international advisory linked at least $10.71 million in thefts and more than 7,000 compromised cryptocurrency wallets to the operation. The attackers deployed remote-access trojans and information stealers, while stolen identity documents and credentials could support impersonation, extortion and further attacks. The campaign complements North Korea’s wider effort to place fraudulent IT workers in overseas companies, reportedly generating up to $500 million annually for the regime.
- Fake recruitment tests infected over 30,000 devices.
- Attackers compromised more than 7,000 crypto wallets.
- Theft proceeds were funnelled to North Korea.