North Korea's Fake Recruiters Infected 30,000 Devices

North Korea's Fake Recruiters Infected 30,000 Devices

By David V. | Category Breaches | 9/22/2026

The Interview That Wasn't

Here's the pitch: a recruiter reaches out on LinkedIn or a freelance platform about a job at a promising AI or crypto startup. The company website looks real. The role looks real. Somewhere in the process, you're asked to complete a coding assignment, or the video call glitches and the "interviewer" walks you through a quick fix for the conferencing software. You run the file. That's the whole attack.

Governments in Japan, the US, Australia, and Germany released a joint advisory on September 18 attributing this campaign to a group they've named WaterPlum — the same operation cybersecurity researchers have tracked as "Contagious Interview" since 2023. Between December 2025 and July 2026, the group compromised at least 30,000 devices across more than 100 countries. It's not a new trick. It's just the first time six government agencies have put their names on the same number. WaterPlum Hit 30,000 Devices via Fake Job Interviews - Gblock +2

What They Actually Stole

The primary targets were web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 — people likely to have crypto wallets sitting on the same machine they use for work. Investigators say the group siphoned funds or seized credentials from more than 7,000 crypto wallets, moving roughly $10.71 million (1.7 billion yen) back to North Korea. North Korean Fake Recruiters Steal $10.7M in Crypto +2

The malware itself isn't a smash-and-grab. The persistent remote access trojans WaterPlum plants can give attackers access to an infected system for months after the "interview" ends. And investigators found the group's operators using AI face-swapping software during video calls, then killing their camera partway through and blaming network problems — a detail that's less "sophisticated hacker" and more "committed to the bit." Tom's HardwareBleeping Computer

The North Korea Connection

This is the part that turns a phishing story into an intelligence story. The advisory attributes WaterPlum, along with some of North Korea's fake remote IT worker operations, to the 313 General Bureau — a unit under the country's Munitions Industry Department, which handles weapons research and production. Same parent organization, two different revenue streams: one poses as job candidates to get hired at real companies, the other poses as recruiters to hire fake ones. Gblock

The two operations reportedly share infrastructure — including the same IP addresses, and stolen identity documents from WaterPlum victims get recycled by North Korean IT workers applying for jobs elsewhere. Japan's National Police Agency also says it dismantled its first domestic "laptop farm" tied to the operation — a setup where a local enabler runs company laptops on North Korean operators' behalf so the hires look like they're logging in from inside the country. WaterPlum Hit 30,000 Devices via Fake Job Interviews - Gblock +2

What You Should Actually Do

If you're job hunting in tech, crypto, or anything adjacent right now, a few habits go a long way:

  • Run coding tests in a sandbox or VM, never on your main machine — and definitely not on the one with your crypto wallets.
  • Read install scripts and config files before you trust a project folder, especially one that arrived from a stranger.
  • Verify the recruiter through the company's own careers page, not just the platform where they messaged you.
  • Be suspicious of urgency — pressure to move fast, switch platforms, or "just run this one fix" is the tell, not the ask itself.
  • If you already ran something sketchy, move your crypto to new wallets and change your passwords from a clean device before you do anything else.

None of this requires you to become paranoid about every recruiter message. It just means treating a stranger's zip file with the same skepticism you'd treat a stranger's USB drive.


🔑 Key Terms

WaterPlum (aka Contagious Interview) — the North Korean hacking group behind this campaign, tracked by researchers since 2023 under the name Contagious Interview before governments formally attributed it as WaterPlum.

RAT (Remote Access Trojan) — malware that gives an attacker ongoing remote control of an infected device, often long after the initial infection.

313 General Bureau — the North Korean unit, under the Munitions Industry Department, that the advisory ties both WaterPlum and parts of North Korea's fake IT worker scheme to.

Laptop farm — a setup where a local operator runs company-issued laptops on behalf of remote workers overseas, making a foreign hire appear to be logging in domestically.

Web3 — the umbrella term for blockchain-based crypto, NFT, and decentralized-app technology; WaterPlum specifically targeted people working in this space.

📚 Sources

BleepingComputer — North Korean WaterPlum hackers infected 30,000 devices worldwide
Forbes — FBI: North Korean Fake Job Interviews Hit 30,000 Devices
Gblock — WaterPlum Hit 30,000 Devices via Fake Job Interviews