Ethical Hacking News
North Korea's deception hiring scams have infected over 30,000 devices, compromising sensitive information and credentials of unsuspecting job seekers worldwide. The WaterPlum scam, orchestrated by North Korean cybercriminals, has already stolen over $10 million in cryptocurrency funds, with the proceeds funnelled to the North Korean regime. As the threat landscape continues to evolve, cybersecurity experts are urging organizations to remain vigilant and take proactive measures to protect themselves against such scams.
The WaterPlum scam has infected over 30,000 devices worldwide, compromising personal data and credentials. Victims are lured into downloading malicious files via fake job interviews, granting attackers persistent access to their devices. The scam has stolen over $10 million in cryptocurrency funds, funneling the proceeds to the North Korean regime. The WaterPlum scam complements North Korea's tactic of placing IT workers in Western and allied companies. Organizations that suspect fraudulent North Korean IT workers should launch a full forensic investigation and assume compromised credentials and data.
In a shocking revelation, international law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US have come together to expose a sophisticated scheme orchestrated by North Korea to infect devices and steal sensitive information from unsuspecting job seekers. The scam, dubbed "WaterPlum" by the agencies, has already infected over 30,000 devices, compromising the personal data and credentials of countless individuals worldwide.
According to the agencies, WaterPlum recruiters use fake job interviews to lure victims into downloading malicious files, which install backdoors on the victims' computers, granting the attackers persistent access to their devices. The attackers then deploy remote access trojans (RATs) and information stealers, allowing them to exfiltrate sensitive data, including cryptocurrency wallet information, identity documents, and credentials.
The scope of the operation is staggering, with the attackers reportedly stealing over $10 million in cryptocurrency funds and funneling the proceeds to the North Korean regime. The agencies estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide, with many working in sanctioned countries that surrender a significant portion of their salaries to the state.
The WaterPlum scam complements North Korea's well-known tactic of placing its own IT workers in technology roles at Western and allied companies. These workers often use AI face-swapping software to create convincing video calls, making it difficult for employers to distinguish between genuine and fake candidates.
The agencies warn that organizations that suspect they have engaged a fraudulent North Korean IT worker should launch a full forensic investigation and assume that credentials and sensitive data have been compromised. The warning comes as researchers continue to uncover new tactics and techniques used by North Korean cybercriminals, including the use of AI model watermarking to manipulate agent behavior.
As the threat landscape continues to evolve, cybersecurity experts are urging organizations to remain vigilant and take proactive measures to protect themselves against such scams. The WaterPlum operation serves as a stark reminder of the need for robust cybersecurity measures and the importance of collaboration between law enforcement agencies and cybersecurity experts to combat the ever-growing threat of state-sponsored cybercrime.
Related Information:
https://www.ethicalhackingnews.com/articles/North-Koreas-Deceptive-Hiring-Scams-A-Threat-to-Global-Cybersecurity-ehn.shtml
https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30000-devices/5297461
Published: Fri Sep 18 13:27:25 2026 by llama3.2 3B Q4_K_M