
It’s believed the stolen cryptocurrency was funneled to the Democratic People’s Republic of Korea (DPRK) government, which also uses fake IT personnel working at legitimate companies to net $500 million annually . The operation also steals credentials and personal data, which it later uses to apply for openings at Western companies. Amazon has seen an example of this in late 2025, with over 1,800 suspected North Korean applications blocked by the company since April 2024.
The attacks occur when fake recruiters ask legitimate applicants to complete coding assignments and other tests to evaluate their skills. However, these often have hidden malware that gives the attackers access to the victim’s computer. These persistent remote access trojans (RATs) allow the WaterPlum group to access an infected system even months after the interview. Since the compromised computer is likely the same device that the targeted applicant will use once they get a legitimate job at another company, it could also be used by the North Koreans as a springboard to attack the systems of and steal credentials from their future clients.
International agencies say these fake recruiters often target software developers and IT professionals with attractive openings, using the names of legitimate AI, cryptocurrency, and NFT companies and posting openings on online job platforms, social media, gig work platforms, and freelance marketplaces. These fake IT workers and similar schemes are used by the hermit kingdom to generate revenue, especially since it has been largely excluded from the wider international economy due to sanctions.
Many companies are aware of this and are taking steps to protect themselves against similar tactics, but it’s probably harder for individual users who are simply looking for opportunities online to do so. Potential applicants can protect themselves by applying only directly with the company and on legitimate platforms, and if they’re unsure about an opening, they should contact the company directly to confirm its legitimacy. If they decide to go to an interview, it would also be wise to set up an isolated virtual machine just for that purpose, giving them an additional layer of protection against potential attacks.
Florida Man arrested after stealing $220,000 in crypto using malware hidden in Steam Games
AI coding agents can be tricked into installing malware via 'clean' GitHub repositories
Fake Go DNS scanner spread malware through over 200 GitHub repos
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/north-korea-used-job-interviews-to-deploy-malware-on-30-000-devices-during-coding-tests-waterplum-group-loots-usd10-7-million-in-crypto-and-plants-persistent-rats#main
- https://www.tomshardware.com/membership
- Nvidia's next-gen RTX 60 GPUs might not be released until 2028, prominent leaker claims — gaming takes a back seat as company focuses on delivering data center
- Techie makes his own motherboard to refurbish 15-year-old HP ProLiant N40L tower server — Raspberry Pi CM5 adds NVMe and USB 3.0
- Acer Nitro XV273U F5 gaming monitor review: One of the fastest LCDs on the planet
- Final Fantasy VII Revelation might use upwards of 200 GB and requires an additional download — latest entry in the series of remakes may set a new record for th
- Researchers build a drone that navigates with physical whiskers to operate in dark, dusty or smoky places where cameras or GPS can fail — sub-100 gram drones ru
Informational only. No financial advice. Do your own research.