Skip to main content
Emerging ThreatsMalware & Ransomware

North Korean Hackers Exploit Job Seekers to Steal Crypto and Data Worldwide

Modern office space with people in background and empty laptop screen in foreground.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote.

WaterPlum / Contagious Interview and its North Korean ties

International security agencies attributed the campaign to a group they called WaterPlum, also known as Contagious Interview, which they said operates under “the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.” The alert was issued jointly by agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.

Impersonation tactics: AI, cryptocurrency, and NFT firms

The agencies said WaterPlum “pose as prospective employers to target software developers and IT professionals worldwide” and “often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.” Those impersonations were used to lure candidates into interactions that led to data theft and follow-on operations.

Laptop farms, shared infrastructure, and IP-address overlap

The alert links WaterPlum’s recruitment ruse to broader North Korean IT operations. “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” the agencies wrote. They added that “WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange,” indicating shared infrastructure between the schemes and other North Korean IT activities.

Scale and financial impact: 30,000 devices and nearly $11 million

According to the alert, the collective operation has infected more than 30,000 devices in more than 100 countries, with IT professionals in Japan, the United States, Europe and other nations singled out as targets. The agencies said WaterPlum’s operations “transferred the equivalent of nearly $11 million of cryptocurrency from over 7,000 crypto wallets to North Korea.” In related enforcement activity, Japanese authorities “successfully identified, investigated, and dismantled a ‘laptop farm’ operated by an enabler in Japan,” and obtained evidence that the cyber actor group “transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan.”

Law enforcement responses: prosecutions, cooperation, and public disclosure

The alert states that law enforcement has had “some success tackling the group” but is seeking further cooperation. The FBI said it “continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers.” Agencies released technical details of WaterPlum’s tactics, techniques and procedures as part of a bid to improve detection and interdiction across borders.

How technologists, policymakers, and job seekers are responding

  • Technologists and security teams: The alert centers on recruitment-based lures and shared infrastructure, signaling that defensive teams should track suspicious employer impersonations, monitor unusual remote-development patterns, and investigate connections to known “laptop farm” activity described by Japanese authorities.
  • Policymakers and prosecutors: The agencies’ joint disclosure and the FBI’s ongoing prosecutions underscore a transnational law enforcement effort; the agencies explicitly requested further cooperation to identify enablers and disrupt transfers of cryptocurrency tied to North Korean actors.
  • Job seekers and IT professionals: The agencies identified software developers and IT professionals as primary targets and warned that actors often pose as AI, cryptocurrency, or NFT firms or use recruiting services to initiate contact.

The advisory frames a multi-threaded campaign that blends social engineering with shared operational infrastructure and financial exfiltration. It also dovetails with a separate international sanctions-monitoring finding: the Multilateral Sanctions Monitoring Team released a report exposing thousands of North Korean nationals employed in industries around the world, a fact the agencies cited to show the breadth of related activity. The agencies’ public disclosure and Japanese law enforcement’s laptop-farm takedown are concrete steps, but the alert makes clear investigators want more international cooperation to trace facilitation networks and the cryptocurrency flows that sustain these operations.

Original story