North Korean cybercriminals posing as recruiters have infected more than 30,000 devices and stolen over $10 million from cryptocurrency holders, according to an international advisory issued Thursday by law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the United States. The agencies track this activity collectively as WaterPlum, a campaign that targets web designers, engineers, and cryptocurrency specialists with fraudulent job interviews. These fake recruitment efforts complement North Korea's better-known tactic of embedding its own IT workers inside Western companies to generate revenue for the regime.
The attackers have compromised more than 7,000 cryptocurrency wallets through this scheme, according to the advisory. During supposed interview processes, victims receive instructions to download files disguised as coding assignments or other recruitment tests. Opening these files backdoors applicants' computers and installs malware. The attackers then deploy remote access trojans and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview concludes. In some cases, the compromised machines later provide a route into corporate systems once jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation.
The advisory states that "stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency." Stolen credentials may be used to take crypto assets, personal data, and trade secrets from victims' employers, clients, or contracting parties, the report notes. The actors can also leverage stolen sensitive information for extortion purposes. The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang.
The recruiter campaign works in tandem with North Korea's sprawling IT worker fraud, which researchers estimate involves roughly 100,000 North Korean IT workers employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. This IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million annually. The scale of the operation means some applicants inevitably succeed, though employers are becoming more familiar with warning signs. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other red flags include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins.
The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. The dual nature of the WaterPlum campaign—both stealing from jobseekers and planting workers inside companies—creates compounding risk for organizations that may face breaches from either direction. Companies now face pressure to balance competitive hiring practices with heightened scrutiny that could slow recruitment without eliminating sophisticated threats designed to exploit the very urgency that makes technology hiring challenging.

