North Korean Hackers Exploit Job Seekers to Steal Crypto and Data, Warn International Agencies
A sophisticated cyber espionage operation has been uncovered by international security agencies, revealing that North Korean hackers are using job postings to gain access to thousands of computer networks worldwide. The threat group, known as WaterPlum or Contagious Interview, is targeting software developers and IT professionals with fake job offers from companies in the AI, cryptocurrency, and NFT sectors.
The operation works by creating a convincing facade of legitimate employment opportunities, often through online recruiting services. Once victims are lured into applying for these positions, the hackers gain access to their computer networks, allowing them to siphon off sensitive information and cryptocurrency. The stolen funds have been valued at nearly $11 million in equivalent US dollars, with over 7,000 crypto wallets compromised.
The overlap between WaterPlum’s activities and those of North Korean IT workers is significant, with shared IP addresses used for accessing “laptop farms” – essentially, large networks of compromised computers used for various nefarious purposes. This has allowed the hackers to maintain a level of anonymity while still leveraging the expertise of their North Korean counterparts.
WaterPlum has successfully infiltrated more than 30,000 devices across over 100 countries, with particular attention paid to IT professionals in Japan, the US, and Europe. The group’s tactics have been so effective that they’ve even managed to transfer hundreds of millions of Japanese yen in cryptocurrency from laptop farms operated within Japan.
While law enforcement agencies have had some success in tackling WaterPlum, more cooperation is needed to fully combat this threat. A recent alert released by the Multilateral Sanctions Monitoring Team, which oversees UN sanctions against North Korea, exposed thousands of North Korean nationals employed worldwide – a worrying trend that highlights the sophistication and scope of these cyber operations.
The takeaway for job seekers and employers alike should be vigilance when dealing with unsolicited job offers or online recruiting services. Legitimate companies typically don’t solicit employees through unsecured email addresses or websites, and it’s crucial to verify the authenticity of any hiring opportunity before sharing sensitive information or accessing company systems.
Source: CyberScoop — 2026-09-18