North Korean Hackers Target Job Applicants with Malware
A sophisticated campaign by the North Korean cyber actor group known as WaterPlum is utilizing fraudulent job postings to install persistent malware on the devices of unsuspecting tech professionals. The operation has resulted in significant financial theft and widespread system compromise.

The Rise of the WaterPlum Cyber Campaign
Government security agencies in the United States, Japan, Germany, and Australia have issued a coordinated warning regarding the activities of the North Korean cyber actor group identified as WaterPlum. As detailed by a recent report from [Tom's Hardware](https://www.tomshardware.com/tech-industry/cyber-security/north-korea-used-job-interviews-to-deploy-malware-on-30-000-devices-during-coding-tests-waterplum-group-loots-usd10-7-million-in-crypto-and-plants-persistent-rats), the group is actively targeting IT professionals and software developers by masquerading as recruiters for AI, cryptocurrency, and NFT companies.
By posting enticing job openings on social media platforms, freelance marketplaces, and specialized job boards, the attackers entice candidates to participate in recruitment processes. The core of the operation involves requiring applicants to perform coding assignments or technical tests, which serve as the delivery vehicle for malicious software designed to compromise personal systems.
Technical Infiltration and Financial Impact
The scale of the operation is significant, with official data indicating that over 30,000 devices have been infected across 100 different countries. Once the malware is successfully deployed through the fake recruitment tests, it establishes a foothold on the victim's computer. The group uses persistent remote access trojans (RATs) to maintain long-term access, often enabling them to operate on the system months after the initial interaction.
The financial damage is equally substantial. The attackers leverage this access to steal sensitive credentials and drain digital assets. To date, the campaign has compromised over 7,000 individual cryptocurrency wallets, leading to confirmed losses of $10.71 million. International observers believe these stolen funds are ultimately funneled to support the government of the Democratic People’s Republic of Korea (DPRK).

A Growing Threat to Enterprise Security
Beyond immediate theft, the campaign poses a systemic risk to the organizations that eventually hire these compromised individuals. Because the malware resides on the applicant's personal hardware—often the same device used for professional tasks—it provides a potential gateway for hackers to breach the security of legitimate corporations.
The threat is not isolated; companies like Amazon have reported taking proactive measures to combat these incursions. Since April 2024, the retail giant has blocked over 1,800 suspected North Korean job applications as part of an effort to maintain [Security](https://www.tomshardware.com/tag/security) across their development teams.
Protective Measures for Job Seekers
As the threat landscape evolves, cybersecurity experts recommend that individuals exercise extreme caution when pursuing remote work opportunities. Candidates are encouraged to verify the legitimacy of any job opening by contacting the company directly rather than relying solely on third-party job boards. Official guidance suggests that applying directly through corporate career pages can mitigate the risk of falling for fraudulent postings.
For those participating in technical interviews that require software installation or coding evaluations, utilizing a sandboxed or isolated virtual machine is considered a best practice. This approach provides an additional layer of protection, preventing malicious code hidden within legitimate-looking coding tests from accessing the primary file system of the applicant's computer.
Sources
- Tom's HardwareNorth Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs