
It’s believed the stolen cryptocurrency was funneled to the Democratic People’s Republic of Korea (DPRK) government, which also uses fake IT personnel working at legitimate companies to net $500 million annually . The operation also steals credentials and personal data, which it later uses to apply for openings at Western companies. Amazon has seen an example of this in late 2025, with over 1,800 suspected North Korean applications blocked by the company since April 2024.
The attacks occur when fake recruiters ask legitimate applicants to complete coding assignments and other tests to evaluate their skills. However, these often have hidden malware that gives the attackers access to the victim’s computer. These persistent remote access trojans (RATs) allow the WaterPlum group to access an infected system even months after the interview. Since the compromised computer is likely the same device that the targeted applicant will use once they get a legitimate job at another company, it could also be used by the North Koreans as a springboard to attack the systems of and steal credentials from their future clients.
International agencies say these fake recruiters often target software developers and IT professionals with attractive openings, using the names of legitimate AI, cryptocurrency, and NFT companies and posting openings on online job platforms, social media, gig work platforms, and freelance marketplaces. These fake IT workers and similar schemes are used by the hermit kingdom to generate revenue, especially since it has been largely excluded from the wider international economy due to sanctions.
Many companies are aware of this and are taking steps to protect themselves against similar tactics, but it’s probably harder for individual users who are simply looking for opportunities online to do so. Potential applicants can protect themselves by applying only directly with the company and on legitimate platforms, and if they’re unsure about an opening, they should contact the company directly to confirm its legitimacy. If they decide to go to an interview, it would also be wise to set up an isolated virtual machine just for that purpose, giving them an additional layer of protection against potential attacks.
Florida Man arrested after stealing $220,000 in crypto using malware hidden in Steam Games
AI coding agents can be tricked into installing malware via 'clean' GitHub repositories
Fake Go DNS scanner spread malware through over 200 GitHub repos
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/north-korea-used-job-interviews-to-deploy-malware-on-30-000-devices-during-coding-tests-waterplum-group-loots-usd10-7-million-in-crypto-and-plants-persistent-rats#main
- https://www.tomshardware.com/membership
- ChatGPT-6 Astra cracks 108-year-old unsolved WWI German code for the first time — radio message sharing enemy movement intelligence had evaded decoding, 1918 Cr
- AI Infra Summit: NVIDIA Vera Rubin and DSX Platform Advancements Showcase Energy Efficiencies of Optimizing Tokens Per Watt for AI Factories
- Father loses job over 9-year-old spending $118,000 on Minecraft YouTube ads using his company's credit card — 'I’m going to be working until I’m like 94,' refus
- AI Infra Summit: NVIDIA Vera Rubin and DSX Platform Advancements Showcase Energy Efficiencies of Optimizing Tokens Per Watt for AI Factories
- Cloudflare saves 100 TB of RAM again, this time by slashing server hashes by 90% — cutting 100,000 entries down to 10,000 eliminates massive cache bloat
Informational only. No financial advice. Do your own research.