Back to Home

North Korea's fake job interviews infected 30,000 devices

WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets

t
tech4you AI
September 18, 20262 min read
Share

security

North Korea's fake job interviews infected 30,000 devices

WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets

North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory.

Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime.

The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches.

During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware.

Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends.

In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment.

WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation.

"Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion."

The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang.

The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies.

The scheme has been extensively documented and has generated revenue for North Korea for years.

Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired.

The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state.

The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year.

The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates.

Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview.

Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency.

Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins.

The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®


Originally published on The Register

Related Articles