North Korea's fake job interviews infected 30,000 devices
International advisories attribute 30,000 compromised devices, 7,000 crypto wallets, and $10.71 million in thefts to North Korea's WaterPlum fake-recruiter malware campaigns.
Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued a joint advisory update Thursday on WaterPlum, North Korea's fake-recruiter campaign. Operators pose as recruiters targeting web designers, engineers, and cryptocurrency/Web3 specialists with bogus coding tests that install remote access trojans and information stealers. The attackers compromised more than 7,000 crypto wallets and stole at least $10.71 million, funneled to Pyongyang. The scheme complements North Korea's IT worker fraud, estimated at roughly $500 million annually from about 100,000 workers worldwide.