Written by Admin Alex · Fact-Checked by M.Ali · Info Verified September 2026
We review and update this article regularly as new information becomes available.
TL;DR: Law enforcement agencies from the US, Japan, Australia, and Germany issued a joint advisory warning about WaterPlum, a North Korean state-backed hacking operation that poses as recruiters to infect job seekers with malware disguised as coding tests. The scheme has compromised more than 30,000 devices and over 7,000 crypto wallets, funneling at least $10.71 million back to North Korea. Web developers, engineers, and crypto specialists are the primary targets.

The recruiter seems legitimate. The job posting looks real. The coding assignment feels like a normal part of any technical interview process. And then you open the file, and it’s already too late.
That’s the mechanism behind WaterPlum, a North Korean state-backed operation that four countries’ law enforcement agencies, the US, Japan, Australia, and Germany, jointly warned about in an advisory issued September 18. The campaign specifically targets web designers, software engineers, and cryptocurrency or Web3 specialists, professions where remote hiring and technical take-home assignments are already completely normal, which is exactly what makes the scam work.
How the trap actually closes
Fake recruiters reach out through legitimate-looking job postings and professional messaging platforms. Once a candidate engages, the “interview” process includes a coding assignment or technical test, delivered as a file. Opening it installs a remote access trojan alongside information-stealing malware. From there, attackers have persistent access to the victim’s system, even after the fake interview process wraps up and the candidate moves on, thinking nothing happened.
The scale here isn’t small. Agencies attribute more than 30,000 compromised devices and over 7,000 breached cryptocurrency wallets to this single campaign, with confirmed financial theft of at least $10.71 million funneled back to North Korea. Stolen data extends beyond crypto wallets to credentials, intellectual property, and identity documents, a haul that suggests the operation isn’t just after quick crypto grabs but longer-term access and data harvesting too.
What actually gives it away
The advisory lists concrete red flags rather than vague warnings. Watch for recruiters who push hard for you to download and run unfamiliar files, who consistently refuse any video call or in-person meeting, whose video calls show visible glitches or artifacts consistent with AI face-swapping tools, or who bring up cryptocurrency payment at any point in the process. Any one of those alone might be nothing. Two or three together is a pattern worth walking away from.
For organizations, the advisory’s guidance is blunter: if you suspect you’ve made a fraudulent hire, or that a candidate interaction involved this kind of scheme, assume credential compromise happened and start a forensic investigation immediately rather than waiting for more obvious signs of a breach.
Why this keeps working
North Korea has run variations of this playbook for years, from fake job offers targeting crypto exchange employees to actual North Korean operatives getting hired as remote IT workers under false identities. WaterPlum represents an evolution of that same underlying strategy: exploit the trust built into remote hiring processes, because remote hiring is now genuinely normal and nobody wants to seem paranoid during a job search.
The tech industry’s shift toward fully remote interviews, especially for contract and freelance crypto work, has made this attack surface bigger than it’s ever been. A scam that would have seemed obviously suspicious a decade ago, when in-person interviews were the default, now blends in seamlessly with how hiring actually works in 2026.
Bottom Line: The uncomfortable truth here is that this scheme works precisely because it mimics normal hiring practices almost perfectly. Until remote interview verification catches up with how sophisticated these campaigns have gotten, the best defense is still old-fashioned skepticism: verify recruiters independently, never run unfamiliar executable files, and treat any resistance to a live video call as a serious warning sign.



