Beneath the ordinary promise of a job offer, a North Korean hacking collective known as WaterPlum turned the ritual of hiring into a weapon, compromising some 30,000 devices across 100 countries and extracting $10.7 million in cryptocurrency from unsuspecting technical professionals. The campaign is a reminder that trust — the quiet faith a job-seeker extends to a prospective employer — is itself a surface that can be exploited. In an era when digital livelihoods and digital assets are inseparable, the boundary between opportunity and intrusion has never been more perilous to navigate.
North Korean WaterPlum hackers infected 30,000 devices via fake job interviews
Fake job interviews as a delivery mechanism for malware
So they just... pretended to be hiring companies and got people to download malware during job interviews?
Exactly. They created fake job postings, conducted what looked like legitimate coding tests, and embedded malware in the process. Candidates thought they were being evaluated for a position.
Do we know which companies they impersonated, or is that still unclear?
The reporting doesn't specify which company names were used in the fake postings. That's a gap.
And 30,000 devices—that's a lot of people. How did they manage that many infections?
The malware gave them persistent remote access, so they didn't have to babysit each one. Once installed, the trojans stayed in place, letting attackers monitor and steal from machines over time.
The $10.7 million figure—is that confirmed theft, or is that an estimate based on wallet movements?
The reporting states it as confirmed theft, but the source material doesn't detail the methodology behind that number. It could be blockchain analysis, victim reports, or a combination.
Why target tech professionals specifically?
They're more likely to have cryptocurrency holdings and access to valuable systems. They're also more likely to download and run unfamiliar software without excessive suspicion during a technical interview.
And we're confident this is WaterPlum and not another North Korean group?
The attribution is based on technical indicators and operational patterns, but attribution to North Korean groups is always probabilistic, not absolute.
What happens to the people whose devices were infected?
They have persistent malware on their machines. Attackers can steal credentials, monitor activity, and potentially move into other systems. Many may not even know they're compromised.
Il Polso
- WaterPlum operatives posed as legitimate tech companies, luring candidates into fake coding interviews that silently installed persistent malware on their machines.
- The infection spread across 100 countries, with 30,000 devices compromised and confirmed victims in Japan and beyond — a scale that signals deliberate, well-resourced coordination.
- Attackers didn't simply strike and vanish; the remote access trojans they deployed were built to linger, enabling ongoing credential theft, network traversal, and long-term surveillance.
- At least $10.7 million in cryptocurrency was siphoned from victims, demonstrating that the campaign was as financially sophisticated as it was technically precise.
- Security researchers have now attributed the operation to WaterPlum based on consistent technical fingerprints, raising urgent questions about whether the group will refine or abandon this recruitment-based playbook under growing scrutiny.
Beneath the ordinary promise of a job offer, a North Korean hacking collective known as WaterPlum turned the ritual of hiring into a weapon, compromising some 30,000 devices across 100 countries and extracting $10.7 million in cryptocurrency from unsuspecting technical professionals. The campaign is a reminder that trust — the quiet faith a job-seeker extends to a prospective employer — is itself a surface that can be exploited. In an era when digital livelihoods and digital assets are inseparable, the boundary between opportunity and intrusion has never been more perilous to navigate.
A North Korean hacking group called WaterPlum has pulled off one of the more psychologically precise cyberattacks in recent memory — not by breaching firewalls, but by impersonating employers. Posing as legitimate technology companies, the group invited job candidates to participate in what looked like routine coding assessments. Hidden inside those evaluations was malware that, once installed, handed attackers persistent, silent access to the victim's machine.
The operation reached across at least 100 countries, infecting roughly 30,000 devices and confirming cases in Japan among many others. From that foothold, WaterPlum stole approximately $10.7 million in cryptocurrency — a figure that reflects not just opportunism, but careful targeting of individuals likely to hold digital assets and possess the technical fluency to be recruited by tech firms in the first place.
What made the scheme so effective was its exploitation of a deeply human dynamic. Job candidates are primed to cooperate — they want to impress, they expect to download tools, and they are unlikely to question a security prompt that appears during what feels like a legitimate technical evaluation. WaterPlum weaponized that cooperative instinct at scale.
The persistent remote access trojans left behind were not designed for a quick smash-and-grab. They were infrastructure — built to monitor, to steal credentials over time, and to move laterally through networks. The operational sophistication required to manage 30,000 infected machines across dozens of countries while coordinating a convincing fake hiring process points to a group with significant resources and long-term intent.
As attribution solidifies and awareness grows, the central question is whether WaterPlum will continue refining this recruitment-based method or adapt in response to increased scrutiny — a question that may already be shaping their next campaign.
A group of North Korean hackers known as WaterPlum has successfully compromised roughly 30,000 devices across the globe by posing as legitimate technology companies conducting job interviews. The scheme worked by inviting candidates to participate in what appeared to be standard coding assessments, then deploying malware during those fake technical evaluations. Once installed, the malware gave attackers persistent remote access to infected machines, allowing them to operate undetected for extended periods.
The scope of the operation is substantial. Victims span at least 100 countries, with confirmed cases in Japan and elsewhere. The attackers used this foothold to steal cryptocurrency, netting approximately $10.7 million from their targets. The use of job interviews as a delivery mechanism is a calculated social engineering tactic—it exploits the trust candidates naturally extend to companies during hiring processes and leverages the technical nature of coding tests to justify asking people to download and run unfamiliar software.
WaterPlum's approach reflects a deliberate shift in North Korean cyber operations toward targeting technology professionals and cryptocurrency holders. Rather than broad-based attacks on infrastructure or financial institutions, this campaign zeroed in on individuals likely to have both technical knowledge and access to digital assets. The persistent remote access trojans left behind mean that even after the initial infection, attackers retained the ability to monitor activity, steal credentials, and move laterally through networks.
The campaign demonstrates how recruitment fraud can serve as a vector for large-scale compromise. Candidates applying for jobs at tech companies are primed to be cooperative—they want to impress potential employers, they expect to download tools, and they may not scrutinize security warnings that appear during installation. By weaponizing this dynamic, WaterPlum was able to cast a wide net and infect tens of thousands of machines with minimal friction.
What makes this operation particularly concerning is its efficiency at scale. Coordinating a fake hiring process across multiple countries, managing 30,000 infected devices, and successfully extracting $10.7 million in cryptocurrency requires operational sophistication and resources. The fact that the group maintained persistent access suggests they were not simply grabbing money and disappearing—they built infrastructure designed to last, to evolve, and to extract value over time.
Security researchers have attributed the campaign to WaterPlum based on technical indicators and operational patterns consistent with known North Korean cyber groups. The targeting of Japan alongside dozens of other nations indicates this was not a geographically limited operation but a global campaign designed to maximize reach and profit. As more organizations become aware of the threat, the question becomes whether WaterPlum will continue refining this recruitment-based attack method or shift tactics in response to increased scrutiny.
Citazioni salienti
WaterPlum group deployed malware through fraudulent coding test interviews, compromising tens of thousands of devices globally with persistent remote access trojans— Security researchers analyzing the campaign