North Korean hackers posed as recruiters to scam IT job seekers across the world. (Photo: Reuters)

North Korean hackers scam IT job seekers, steal Rs 100 crore

A North Korean hacking group called WaterPlum scammed IT job seekers worldwide. The group gained access to 30,000 devices by sending malicious files to job seekers and stole roughly Rs 100 crore in cryptocurrency.

by · India Today

In Short

  • The campaign ran from December 2025 to July 2026 across countries
  • Hackers stole credentials from over 7,000 cryptocurrency wallets and accounts
  • Victims were asked to run files during interviews or coding tests

North Korean hackers managed to scam thousands of IT job seekers in over 100 countries, stealing roughly Rs 100 crore, according to a joint advisory issued by authorities from Japan, the United States, Australia and Germany. The group, called WaterPlum and also known as Contagious Interview, posed as job recruiters. They targeted software developers, web freelancers and other IT professionals by offering job opportunities and then tricking them into downloading malicious files.

As per the advisory, the campaign ran from December 2025 to July 2026. During that period, the group obtained funds or account details from more than 7,000 cryptocurrency wallets and transferred 1.7 billion Japanese yen, or about Rs 100 crore to North Korea.

Officials said the group has been active since 2023 and has carried out both financially motivated attacks and cyberespionage.

How did hackers scam IT job seekers?

Authorities said WaterPlum contacted job seekers through social media platforms, online job portals, gig work sites and freelance marketplaces. They often posed as recruiters or employees of AI or cryptocurrency companies. People who responded were asked to attend virtual technical interviews or complete coding assignments.

During these interactions, the candidates were told to download and run files to prove their skills or to fix a supposed video-conferencing problem. One line cited in the advisory read, “I would like to verify your technical abilities, so please download the specified file and complete the assigned task.”

Once a candidate downloaded the file, the hackers used malware and remote-access tools to maintain access to the device and steal data. The information taken included browser login details, passwords, screenshots, clipboard data, recorded keystrokes, files, cryptocurrency-wallet data, and identity documents such as driving licences and passports. The advisory named malware families such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.

Officials said the damage was not limited to individual victims. If an infected device belonged to a developer working for a company, the hackers could use that machine as a path into the employer’s network. That could expose source code, credentials, trade secrets and other sensitive material, and could lead to further espionage or theft of intellectual property.

The agencies urged companies and IT professionals to stay alert, avoid running code from unknown third parties, check suspicious files and projects carefully, and isolate systems immediately if an infection is suspected.

North Korean IT workers hide identities to work abroad

The advisory also said the operation overlapped with a separate scheme involving North Korean IT workers who hid their identities and locations to win remote work from companies abroad.

Investigators found that WaterPlum actors and these fraudulent IT workers used the same IP addresses while accessing crowdsourcing services, laptop farms and job applications sent to a Japanese cryptocurrency exchange. A laptop farm is a setup, often run by an enabler, where computers are kept in one country and remotely operated from another location to hide the user’s true whereabouts.

Japanese authorities said they identified, investigated and dismantled a laptop farm in Japan for the first time. The advisory said North Korean IT workers used identity images supplied by enablers to impersonate real people, and obtain contracts. The workers then received payments, sometimes through third-party accounts or in cryptocurrency. Investigators said evidence showed several hundred million yen, including cryptocurrency assets, had been moved abroad.

Authorities also described cases in which these workers allegedly took further malicious action. In one case, a worker extorted a company over payment and published its proprietary source code online. In another, a worker hired for website maintenance defaced the company’s website and made it inaccessible.

In one case from May 2025, a Japanese cryptocurrency exchange received an engineering application from a person suspected to be a North Korean IT worker. The applicant claimed to be from Malaysia and living in Finland, but the company found that his English and technical explanations did not match the qualifications listed in the resume and did not hire him.

Investigators also said WaterPlum members at times used AI face-swapping software during online interviews, then claimed network problems and asked the other person to switch off video. On holidays celebrated in North Korea, the members were seen playing games and watching football videos instead of carrying out their usual activity.

North Korean hacking groups have been involved in several such cases in the past. The Lazarus Group – a state sponsored hacking group – reportedly stole about $1.5 billion in Ethereum from ByBit last year. State-linked groups have also allegedly stolen hundreds of millions of dollars. In 2017, the infamous WannaCry attack – linked to North Korea – affected more than 150 countries, and crippled the UK’s National Health Service (NHS). A year earlier, North Korean-linked hackers stole $81 million from Bangladesh Bank.

- Ends