Global probe ties North Korean group to mass device compromise and crypto theft

A joint advisory from Japanese, US, Australian, and German authorities attributes a campaign that infected at least 30,000 devices across over 100 countries to the North Korean hacking group WaterPlum. The operation, linked to the 'Contagious Interview' scheme, used fake job offers and malicious packages to steal credentials and cryptocurrency, transferring over $10.7 million to North Korea. The advisory details multiple malware families and warns of potential network pivoting for espionage.
The advisory identifies a sophisticated social engineering pipeline, where fake recruitment processes on freelance platforms deliver malicious code disguised as legitimate technical tasks. WaterPlum operators reportedly use AI face-swapping during video interviews before disabling cameras, while some operatives simultaneously work as remote IT contractors, blurring lines between espionage and fraud. Investigators also uncovered a "laptop farm" in Japan, suggesting infrastructure for laundering stolen identities and funds.
The campaign's reach spans over 100 countries, with attackers pivoting from credential theft to corporate network infiltration. By reusing stolen identity documents for fraudulent employment, the group extends its operational lifespan beyond initial compromises, creating persistent access to victim networks and enabling long-term intelligence gathering alongside financial theft.
This campaign could significantly undermine trust in remote hiring practices, particularly in tech sectors where coding assessments are standard. Job seekers may become wary of legitimate opportunities, while companies face increased screening costs and liability. The theft of credentials and cryptocurrency directly harms individuals, but the network pivoting threat could expose corporate intellectual property, affecting broader economic security. The scale—30,000 devices—suggests this may represent a systemic vulnerability in global digital recruitment, potentially reshaping how organizations verify remote workers and handle sensitive data.