Bottom line: North Korean cybercriminals are using fake job offers to infect the computers of technology workers, steal cryptocurrency and collect information that can be used in later attacks. Authorities in Australia, Germany, Japan and the United States said the operation has compromised more than 30,000 devices and more than 7,000 cryptocurrency wallets. The campaign has generated at least $10.71 million, which investigators said was ultimately directed to North Korea.
The agencies refer to the group behind the activity as WaterPlum. It targets web designers, software engineers and people working in cryptocurrency and Web3. The group contacts victims while posing as recruiters, then sends what appears to be a coding exercise or other technical test as part of the hiring process.
The files contain malware. Once a target downloads and opens one, the attackers can install remote-access tools and information stealers on the computer. That gives them continuing access to the system after the supposed interview is over.
The malware can collect login credentials, clipboard data, keystrokes, cryptocurrency-wallet information, identity documents and proprietary files. The risk can extend to a victim’s employer if the person later uses the compromised computer for legitimate work.
The agencies said stolen identity documents may also help North Korean IT workers conceal their identities while seeking jobs abroad. “Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency,” the advisory said.

The stolen credentials can be used to take cryptocurrency, access personal data or obtain trade secrets from employers, clients and contractors, the advisory said. The attackers may also use sensitive material in extortion attempts.
The campaign is tied to a wider North Korean effort to generate money through remote IT work. In that scheme, North Korean workers use false identities to get jobs with companies in the US and other countries that sanction North Korea. They collect salaries, with much of the money going back to the government.
Researchers estimate that about 100,000 North Korean IT workers are employed or looking for work around the world. Some use laptop farms operated by accomplices to make it appear they are working from the country where they were hired. These activities may bring in more than $500 million a year for North Korea.
Companies have grown more familiar with signs that a job candidate may be using a false identity. Applicants may present impressive résumés that do not match their performance in interviews. Some refuse to meet in person, have repeated technical issues during video calls or ask to be paid in cryptocurrency.
North Korean workers may also use AI face-swapping tools during interviews. The software can leave visual glitches, and some candidates turn off their cameras shortly after a call begins.
Authorities recommend that companies that suspect they hired a fraudulent North Korean IT worker conduct a full forensic investigation. They should assume that passwords, systems and sensitive data may have been exposed.

