Fake coding tests from North Korean hackers compromise 30,000 devices and drain $10.7M in crypto

Security agencies in Japan, the U.S., Australia, and Germany have issued a joint advisory about a North Korean hacking group called WaterPlum that uses fake job postings to trick applicants into running malware-laced coding tests. The operation has infected over 30,000 devices across 100 countries, compromised more than 7,000 cryptocurrency wallets, and stolen $10.71 million, which is believed to fund the DPRK government. The attackers install persistent remote access trojans that allow them to maintain control of victims' computers long after the interview process.
The WaterPlum campaign exploits the trust job seekers place in recruitment processes, weaponizing coding assessments to deliver persistent remote access trojans. Victims remain compromised long after interviews conclude, with attackers able to revisit infected systems repeatedly. The stolen funds, totaling over $10 million in cryptocurrency, are believed to support DPRK state operations, supplementing an estimated $500 million annually generated through fake IT workers embedded in legitimate companies.
The scheme specifically targets software developers and IT professionals, using fabricated job listings that borrow names from real AI, cryptocurrency, and NFT firms. These postings appear across mainstream platforms including job boards, social media, and freelance marketplaces. Amazon alone has blocked over 1,800 suspected North Korean applications since April 2024, highlighting the scale of this ongoing infiltration effort.
This operation could significantly erode trust in remote hiring practices, particularly in tech sectors where coding assessments are standard. Job seekers may become hesitant to complete legitimate pre-employment tests, potentially slowing hiring pipelines and forcing companies to redesign evaluation methods. The persistent access gained through these attacks could also create downstream risks for employers who unknowingly hire compromised individuals, potentially exposing client data and corporate systems to state-sponsored actors. Individual victims face financial losses and long-term device compromise that may go undetected for months.