Fake IT Job Interviews Help North Korea Steal Millions in Crypto

4 hours ago 33

A North Korean state-backed hacker group infected over 30,000 computers across 100 countries with malware that stole millions of dollars in crypto between late 2025 and July 2026.

Key Takeaways

  • North Korea’s WaterPpum group compromised 30,000 devices via fake tech interviews between Dec 2025 and July 2026.
  • Over 7,000 crypto wallets were breached, draining $10.71M and destabilizing freelance tech recruitment systems.
  • The NPA, FBI, and global allies urge firms to enforce sandbox environments to prevent future software exploits.

Fake Job Interviews Used as Bait

A North Korean cyberattack campaign disguised as legitimate tech recruitment has infected more than 30,000 computers across at least 100 countries, stealing thousands of cryptocurrency wallets and millions of dollars to fund Pyongyang’s weapons programs, law enforcement agencies from six nations warned.

In a joint security advisory issued Sept. 18, Japan’s National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI), alongside cyber and intelligence agencies from Australia and Germany, detailed the global operations of a threat actor known as “Waterplum,” also tracked internationally as “Contagious Interview.”

Authorities assessed that Waterplum and associated North Korean IT workers operate under the direct oversight of Bureau 313 of the Munitions Industry Department of the Workers’ Party of Korea, which manages North Korea’s military research and weapons production.

According to Japanese investigators, Waterplum targeted software developers, web designers, and cryptocurrency specialists on job platforms and social media by posing as recruiters from legitimate artificial intelligence, blockchain, and tech recruitment companies.

During fake technical interviews or coding assessments, target candidates were instructed to download malicious software disguised as coding tests or video conferencing troubleshooting tools. Once executed, the code delivered backdoor trojans and information-stealing malware, allowing hackers to harvest personal identification documents and cryptocurrency private keys.

Between late 2025 and July 2026, the campaign compromised at least 30,000 devices worldwide, compromising more than 7,000 cryptocurrency wallets and funneling at least 1.7 billion yen ($10.71 million) in digital assets into North Korean-controlled wallets, officials said.

‘Laptop Farms’ Uncovered in Japan

The investigation also highlighted the role of “domestic enablers” who helped North Korean operatives bypass location verification and land outsourced IT jobs at Japanese and U.S. firms.

In a first for Japanese law enforcement, police seized and dismantled a local “laptop farm” that permitted remote North Korean IT workers to operate under local IP addresses. Authorities noted that illicit IT workers operating through these schemes transferred hundreds of millions of yen worth of crypto assets overseas.

International security agencies urged tech companies and gig workers to exercise caution during online interviews, avoid executing unvetted code outside isolated sandbox environments, and utilize workspace restriction controls when opening untrusted code repositories.

Read Entire Article