WaterPlum Turns Fake Job Interviews Into a Gateway for Crypto Theft and Corporate Intrusion

North Korea-linked WaterPlum used fake job interviews to infect 30,000 devices, steal $10.5M in crypto and gain access to corporate networks.

Text generated by artificial intelligence, published without human review. AI transparency

WaterPlum Turns Fake Job Interviews Into a Gateway for Crypto Theft and Corporate Intrusion
APT

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

A North Korean-linked campaign is using fraudulent recruitment processes to infect technology professionals, steal cryptocurrency and maintain access that could later extend into corporate networks.

Known as WaterPlum, the operation compromised at least 30,000 devices across 100 countries between December 2025 and July 2026. Investigators estimate that the attackers stole funds or credentials associated with approximately 7,000 cryptocurrency wallets, generating more than $10.5 million in cryptocurrency and other illicit proceeds.

The victims include web designers, engineers, blockchain developers and cryptocurrency specialists. IT professionals in Japan were specifically identified among those affected.

Recruitment lures deliver multiple malware families

WaterPlum begins where candidates expect routine professional contact. Operators approach targets through social networks, freelance marketplaces, gig-work services and other recruitment channels, while posing as recruiters for AI or blockchain businesses.

During an interview or technical assessment, the supposed recruiter asks the candidate to download a file or install software. The material appears connected to the hiring process but instead initiates an infection on the applicant’s device.

Japanese authorities found five malware families on compromised systems:

  • BeaverTail
  • InvisibleFerret
  • OtterCookie
  • OtterCandy
  • StoatWaffle

The operators generally combined information-stealing malware with remote-management capabilities. That toolset allowed them to collect credentials and other data, compromise cryptocurrency wallets and preserve access to infected computers.

The available information does not identify the exact file formats, delivery URLs, command-and-control infrastructure or persistence mechanisms used in every infection. It also does not provide hashes or other indicators that defenders could use for direct matching.

This is not merely a one-time wallet theft technique. Persistent access gives the attackers additional opportunities after the initial compromise.

A personal infection can become a corporate breach

WaterPlum’s strategic value lies in the position of its targets. Engineers and developers often hold credentials for source-code repositories, cloud platforms, cryptocurrency systems and internal collaboration services.

A candidate may also secure a new job after their personal computer has been compromised. If that device remains infected, the attackers could exploit newly issued accounts or access company resources through the victim.

That creates a path from a deceptive interview to a future employer’s environment. Potentially exposed assets include corporate credentials, proprietary code, internal systems, websites and digital-asset infrastructure.

Incident responders had previously tracked related activity using the same malware families against blockchain developers contacted by fake recruiters on LinkedIn. Attacks on personal devices in that operation reportedly produced as much as $12 million in cryptocurrency theft. At least one blockchain company has acknowledged that a related technique contributed to a substantial loss.

Comparable recruitment-themed campaigns have targeted defense-sector applicants since 2020. In 2022, Google warned that 250 people at 10 organizations had received malicious approaches from purported recruiters claiming to represent Disney, Google and Oracle. The targeted organizations included news companies, domain registrars, hosting providers and software vendors.

Investigators connect WaterPlum with North Korean employment fraud

The joint investigation into WaterPlum involved the FBI, the U.S. Department of Defense, Japan’s National Police Agency, and law-enforcement bodies in Australia and Germany.

Investigators linked the campaign to North Korea’s wider use of fraudulent IT workers. In those operations, individuals steal or purchase identities and use them to obtain well-paid technology positions in the United States or Europe.

The relationship is supported by infrastructure overlap. WaterPlum operators and North Korean IT workers were observed using the same IP addresses while accessing laptop farms or applying for jobs at Japanese cryptocurrency companies.

Laptop farms allow a remote worker to appear as though they are connecting from the employer’s country. U.S. authorities have uncovered dozens of these operations. Japanese officials also disrupted a laptop farm allegedly operated by a Japanese national and found evidence that several hundred million Japanese yen had been transferred to addresses outside Japan.

The employment candidates used AI-enabled tools to reinforce their false identities. Investigators observed face-swapping software, text-to-speech systems capable of producing Japanese pronunciations and other AI translation technology.

These capabilities can help an applicant conceal their appearance, manage language barriers and maintain a fabricated persona during remote interviews. They do not eliminate inconsistencies, but they make identity verification based solely on video calls or conversational fluency less dependable.

Financial operations can escalate into sabotage and extortion

Cryptocurrency theft and wage generation remain central objectives, but the documented activity extends beyond revenue collection.

In one case, a worker allegedly attempted to extort an employer during a payment dispute and then published proprietary source code. In another, a person hired to maintain a website defaced it and caused the site to become unavailable.

Such incidents complicate the distinction between an external attacker and a malicious insider. An employer may believe it has hired a legitimate remote employee while actually granting an adversary access to repositories, production systems and confidential business information.

The campaign and several associated IT-worker operations were attributed to North Korea’s General Bureau of the Munitions Industry Department, part of the Central Committee of the Workers’ Party of Korea.

Multiple North Korean government departments have previously been assessed as operating cyber teams that generate revenue through legitimate IT employment, cryptocurrency theft and data extortion. WaterPlum appears to connect several of those methods: recruitment fraud supplies victims, malware produces credentials and wallet access, and persistent compromise creates opportunities for later intrusion.

Job seekers should separate recruitment from valuable assets

No campaign-specific remediation procedure has been disclosed. In particular, there is no published universal removal method covering all five named malware families.

Job seekers can nevertheless reduce exposure by treating unexpected interview files, coding exercises and software-installation requests as untrusted. Recruiters and employers should be verified through independently obtained contact details rather than information supplied in the initial message.

A device used for applications should not also hold cryptocurrency wallets, wallet recovery phrases or privileged access to an employer. Where practical, candidates can perform interviews and assessments in an isolated environment without access to personal secrets or corporate accounts.

Any system that executed a suspicious recruitment file should be removed from sensitive networks and investigated. Defenders should search for:

  • BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle;
  • unauthorized remote-management utilities;
  • unfamiliar wallet transactions or credential changes;
  • unexpected outbound network connections;
  • new persistence mechanisms or unknown user accounts;
  • access to code repositories and cloud services from unusual locations.

Because specific malicious IP addresses have not been disclosed, organizations cannot rely on a complete infrastructure blocklist. Where lawfully available, security teams should examine connections associated with known laptop-farm infrastructure and investigate unexplained overlaps between applicants, remote workers and cryptocurrency-focused systems.

Employers need stronger checks before granting access

Companies face two related risks: a real applicant whose computer was infected by WaterPlum, and a fraudulent applicant seeking employment on behalf of a North Korean operation.

Identity and employment-history checks should therefore use independent channels. A successful video interview alone is insufficient, particularly when face-swapping, synthesized speech and automated translation can support a false identity.

New employees should initially receive only the access required for their role. Repository permissions, cloud privileges, production credentials and cryptocurrency controls should be added gradually and monitored for abnormal use.

Recruitment teams also need a controlled process for distributing assessments. Organizations should avoid asking candidates to run opaque packages or unofficial software, and should provide verifiable download locations when tools are genuinely required.

WaterPlum exploits trust before a formal employment relationship exists. Its operators use that initial access for immediate theft, but the longer-term objective may be more damaging: carrying an undetected foothold from a candidate’s personal device into the next company that hires them.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsWaterPlumNorth Korean hackersfake job interviewscrypto theftcorporate intrusionBeaverTail malwarerecruitment scam
Back to home