Protect.Computer
NEWS

North Korean Hackers Infected 30,000 Devices in Fake Job Scam

· 1 min read · Got hacked Malicious byte
North Korean Hackers Infected 30,000 Devices in Fake Job Scam

A joint advisory from law enforcement and cybersecurity agencies in the United States, Japan, Australia, and Germany has identified a North Korean hacking group called WaterPlum as the source of a sweeping campaign that infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026. The group stole over $10.7 million in cryptocurrency, harvested login credentials from more than 7,000 crypto wallets, and transferred the funds to North Korea.

WaterPlum is linked to the long-running “Contagious Interview” campaign that targets software developers and job seekers. Attackers impersonate AI, cryptocurrency, or NFT companies on freelancing and recruiting platforms, invite targets to fake technical interviews, then ask them to download a test project or “troubleshoot” video-conferencing software. The download is malware. Once installed, it harvests browser credentials, clipboard contents, keystrokes, cryptocurrency private keys, and documents — and takes periodic screenshots. Investigators also confirmed that some WaterPlum operators simultaneously pose as legitimate remote IT workers, and that the group uses AI face-swapping software during video calls to conceal their identities. North Korea’s 313 General Bureau, which oversees the country’s weapons research programs, is assessed to be running the operation.

How to check if you’re affected

Affected devices are any computer used to download code, run scripts, or install software during an online technical interview or freelance coding test in the past 12 months — especially if the recruiter was on LinkedIn, Upwork, or Telegram rather than a company’s official careers page. Specific red flags: the “company” asked you to clone and run a git repository, fix a video-conferencing bug by running a terminal command, or install a custom npm package before the interview started. If any of those steps happened on your primary machine, treat it as potentially compromised: change passwords for banking, email, and any cryptocurrency accounts, revoke active sessions, and check recently installed programs and browser extensions for anything unfamiliar.

Sources

Related reading