North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs
Multiple government agencies across the world released a warning that North Korean hackers are posting fake jobs to install malware on unsuspecting applicants' computers. They then steal credentials and cryptocurrency from their victims, with over $10 million reported stolen.
Japanese, U.S., Australian, and German security agencies have warned of a North Korean cyber threat group known as "WaterPlum." This group has been deploying malware on the devices of job applicants through fraudulent job postings, stealing their credentials and cryptocurrency holdings. Over 30,000 devices across 100 countries have been infected, and more than 7,000 cryptocurrency wallets have been compromised, resulting in losses of $10.71 million.
The stolen cryptocurrency is believed to be funneled to the North Korean government, which uses fake IT personnel at legitimate companies to generate $500 million annually. The WaterPlum group also steals credentials and personal data, using them to apply for openings at Western companies. Amazon has blocked over 1,800 suspected North Korean applications since April 2024.
The attacks involve fake recruiters giving applicants coding assignments to evaluate their skills, which often contain hidden malware. This allows the attackers to maintain access to the victim's computer even after they secure a legitimate job, potentially enabling further attacks on their future clients. The fake recruiters typically target software developers and IT professionals with enticing job openings, using the names of legitimate AI, cryptocurrency, and NFT companies on various online platforms.
To protect themselves, potential applicants should apply directly with companies and on legitimate platforms, confirm the legitimacy of job openings by contacting the company directly, and set up an isolated virtual machine for interviews to minimize the risk of infection.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.