North Korean Hackers Posed as Recruiters, Infected 30,000 Devices Worldwide, Advisory Says
A joint advisory from Japanese, Australian, German and U.S. authorities says North Korean hackers posed as recruiters to infect about 30,000 devices in over 100 countries and drain more than $10 million in cryptocurrency.
Slashdot reported that the advisory was issued with participation from the Federal Bureau of Investigation and the Defense Department's Cyber Crime Center, and that it covers attacks carried out between December 2025 and July 2026. The group, identified as WaterPlum, has been active since 2023, conducting both financially motivated attacks and cyberespionage, according to the advisory.
The campaign starts with fake job listings aimed at software developers and IT professionals. The hackers approach job seekers through social media, online job platforms, gig-work sites and freelance marketplaces, then ask them to take part in virtual technical interviews or complete coding assignments. Targets are told to download and run malicious files, sometimes under the guise of finishing an assignment or troubleshooting a problem with videoconferencing software.
Those files are hosted on multiple online collaboration software developer platforms and code repositories, the advisory says, and include malicious Node Package Manager packages. Once the group gains access to a device or network, its malware steals browser passwords, screenshots, files and cryptocurrency-wallet data. Authorities said an infected computer can also serve as an avenue into the network of the victim's employer, opening the door to intellectual property theft and espionage.
The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad. Stolen identification images can also be used by North Korean IT workers to impersonate victims in order to obtain contracts and receive payment in foreign currency, and the advisory states that the actors can use stolen sensitive information for extortion as well. In one case, a North Korean IT worker extorted a company over payment and published its proprietary source code online. In another, an IT worker hired for website maintenance defaced the hiring company's website and made it inaccessible.
The advisory offers employers clues about the workers. It warns that they tend to favor payment in cryptocurrency and may ask for remuneration to be sent to an account in another person's name. During interviews, they have sometimes used AI face-swapping software and then claimed network issues and disabled their video. On holidays celebrated in North Korea, the advisory notes, the actors played games and watched soccer videos instead of carrying out their usual malicious activity.
Editor's Summary
A joint advisory from authorities in Japan, Australia, Germany and the United States says North Korean actors used fake developer recruiting pitches to infect roughly 30,000 devices across more than 100 countries between December 2025 and July 2026, taking over $10 million in cryptocurrency from 7,000 wallets. The advisory links the campaign to a wider effort by North Korean IT workers to win remote jobs abroad and use stolen identities for contracts, payments and extortion. It advises employers to treat cryptocurrency payment requests, AI face-swapping in interviews and requests to run downloaded files as warning signs.