Skip to content
Tech News
← Back to articles

North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

This story matters because it shows how North Korean state-sponsored hackers are exploiting the hiring process itself—a routine, trusted activity for job seekers and companies alike—to infiltrate systems at scale. With 30,000 devices compromised across 100 countries and over $10 million in crypto stolen, it highlights a growing threat vector that blends social engineering with technical exploitation, putting both individuals and the companies they later work for at risk.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — With North Korean actors targeting job applicants through fake coding tests to steal credentials and crypto, hardware-based authentication like a YubiKey adds a physical barrier attackers can't replicate remotely. It's a practical step for developers and crypto holders who want phishing-resistant login protection beyond passwords.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Security agencies in Japan, the U.S., Australia, and Germany warned that the North Korean “WaterPlum” cyber actor group has been installing malware on applicants to fake job postings and stealing their credentials and cryptocurrency holdings. The advisory [PDF] says more than 30,000 devices across 100 countries have already been infected and more than 7,000 cryptocurrency wallets have been compromised, leading to losses of $10.71 million.

It’s believed the stolen cryptocurrency was funneled to the Democratic People’s Republic of Korea (DPRK) government, which also uses fake IT personnel working at legitimate companies to net $500 million annually. The operation also steals credentials and personal data, which it later uses to apply for openings at Western companies. Amazon has seen an example of this in late 2025, with over 1,800 suspected North Korean applications blocked by the company since April 2024.

The attacks occur when fake recruiters ask legitimate applicants to complete coding assignments and other tests to evaluate their skills. However, these often have hidden malware that gives the attackers access to the victim’s computer. These persistent remote access trojans (RATs) allow the WaterPlum group to access an infected system even months after the interview. Since the compromised computer is likely the same device that the targeted applicant will use once they get a legitimate job at another company, it could also be used by the North Koreans as a springboard to attack the systems of and steal credentials from their future clients.

Latest Videos From Tom's Hardware Watch full video here:

International agencies say these fake recruiters often target software developers and IT professionals with attractive openings, using the names of legitimate AI, cryptocurrency, and NFT companies and posting openings on online job platforms, social media, gig work platforms, and freelance marketplaces. These fake IT workers and similar schemes are used by the hermit kingdom to generate revenue, especially since it has been largely excluded from the wider international economy due to sanctions.

Many companies are aware of this and are taking steps to protect themselves against similar tactics, but it’s probably harder for individual users who are simply looking for opportunities online to do so. Potential applicants can protect themselves by applying only directly with the company and on legitimate platforms, and if they’re unsure about an opening, they should contact the company directly to confirm its legitimacy. If they decide to go to an interview, it would also be wise to set up an isolated virtual machine just for that purpose, giving them an additional layer of protection against potential attacks.

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.