That blunt sentence heads an international warning issued Thursday after a recruiter-style campaign tied to North Korea compromised more than 30,000 devices and helped steal funds the agencies say ultimately supported the regime. Authorities from Australia, Germany, Japan, and the United States published an update attributing the activity — tracked collectively as WaterPlum — to operators who pose as recruiters to infect job applicants, harvest credentials and identity data, and siphon cryptocurrency.
WaterPlum's recruitment ruse and the infection vector
WaterPlum operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. The advisory says victims are led through a supposed interview process and instructed to download files presented as coding assignments or other recruitment tests. When opened, those files "backdoor" the applicants' computers and install malware.
The campaign has compromised more than 30,000 devices and more than 7,000 cryptocurrency wallets, according to the advisory. The agencies attributed at least $10.71 million in thefts to these tactics, and they say the proceeds were funnelled to Pyongyang.
Malware types, persistence, and what is taken
Once inside a machine, the attackers deploy remote access trojans (RATs) and information stealers that provide persistent access to credentials and other sensitive data long after the fake interview ends. The advisory lists the kinds of material the operators seek: intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents.
That persistence matters for two reasons the agencies highlight. First, stolen credentials can be used directly to exfiltrate crypto assets and personal data. Second, compromised jobseekers who later obtain legitimate employment can unwittingly provide a route into employer networks, allowing attackers to pivot from personal devices to corporate systems.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow the campaign fits into North Korea's broader IT-worker schemes
The advisory places WaterPlum alongside a better-known tactic in which North Korea places its own IT workers in technology roles at Western and allied companies. Researchers cited in the notice estimate roughly 100,000 North Korean IT workers are employed or seeking work worldwide, some supported by "laptop farms" that make remote workers appear to be based in the country where they were hired.
The report says the broader sprawling fraud — salaries collected in countries that impose heavy sanctions and then surrendered to the state — is thought to net "Kim Jong Un's regime upwards of $500 million a year." The recruiter campaign is described as a complement to that scheme: a parallel way to harvest assets, credentials, and identity data that can be monetized or used for further impersonation and extortion.
Signs of fraudulent candidates and recommended defensive steps
The advisory lists practical red flags employers and applicants should watch for. Fraudulent candidates may submit strikingly impressive resumes that crumble under questioning; they often refuse to meet in person, show suspicious interruptions to video feeds, have voices in the background, or ask for payment in cryptocurrency. The agencies also warn that fraudulent workers may use AI face‑swapping software — visual artifacts during video calls and a rapid decision to disable a camera are specific giveaways.
Where organizations suspect they have engaged a fraudulent North Korean IT worker, the agencies recommend launching a full forensic investigation and assuming that credentials and other sensitive data have been compromised.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Follow the advisory's guidance — conduct forensic investigations when suspicious recruitment contacts are suspected, assume credential compromise, and hunt for lateral access from personal devices to corporate systems.
- Policymakers and international authorities: The coordinated advisory from Australia, Germany, Japan, and the United States signals cross-border concern about cryptocurrency-derived funding streams and identity-fraud mechanisms that sustain state-directed revenue collection.
- Affected enterprises and hiring managers: Tighten vetting for remote hires in the targeted specialties (web design, engineering, crypto/Web3), watch for the specific interview and video-call red flags named in the advisory, and treat unsolicited code-assignment files from unknown recruiters as potential malware.
The WaterPlum advisory ties a familiar-sounding recruitment pitch to concrete criminal tradecraft: social engineering that leads to malware installation, persistent access through RATs and information stealers, and targeted theft of crypto and identity data. The agencies have quantified the impact — tens of thousands of infected devices, thousands of compromised wallets, and more than $10 million attributed losses — and urged impacted organizations to assume compromise and investigate. The next practical test will be how widely those recommendations are adopted where hiring is remote, specialized, and cross-border.
Original story: https://www.theregister.com/security/2026/09/18/north_koreas_fake_job_interviews_infected_30000_devices/5297461




