Trending: On-device modelsSearch
iHeartGeek
iTECH

North Korea's fake recruiters hit 30,000 devices

Seven agencies in four countries say North Korean operators posing as AI and crypto recruiters have infected at least 30,000 devices and moved $10.7m in crypto to Pyongyang.

A hooded figure seated in a dark room working at a laptop, lit by the cold blue glow of the screen, with a second monitor glowing amber in the background

If a recruiter from an AI or crypto company slides into your inbox this week, there is a measurable chance the job is real and the company is not. Seven agencies across four countries warned on 18 September that the North Korean group tracked as WaterPlum - better known as Contagious Interview - is running fake recruitment at industrial scale.

The figures in the joint advisory are blunt. WaterPlum has infected at least 30,000 devices in more than 100 countries and pulled credentials or funds from over 7,000 cryptocurrency wallets. Roughly 1.7 billion yen, about $10.7m, has been moved to the Democratic People's Republic of Korea.

Who signed the warning

The advisory carries the names of Japan's National Police Agency and National Cybersecurity Office, the FBI, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, Germany's Federal Intelligence Service and its domestic security service, the BfV. The NPA and the FBI assess that WaterPlum's operators and some North Korean IT workers sit under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers Party of Korea.

How the scam works

Operators pose as prospective employers and target software developers and IT professionals worldwide, holding out attractive jobs. They impersonate artificial intelligence, cryptocurrency and NFT companies, and they have also used real recruiting services as cover. Once a target takes the call, opens the coding test or installs the company app, the network belongs to someone else.

Some of the same people then take contracts as North Korean IT workers, doing web system design and development for clients. That overlap is not incidental. The agencies say WaterPlum operators and North Korean IT workers used the same IP addresses when reaching laptop farms, using cloud-sourcing services and applying for positions at a Japanese cryptocurrency exchange.

The first laptop farm to fall

Japanese authorities identified, investigated and dismantled a laptop farm run by an enabler, a first for the country, and obtained evidence that the group moved several hundred million yen in cryptocurrency out of Japan. The FBI says it continues to identify and prosecute US-based facilitators who provide illicit services to North Korean IT workers.

Our opinion

The uncomfortable part of this advisory is how ordinary the attack is. WaterPlum does not need a zero-day when a plausible job offer gets it past the front door, and 30,000 devices is simply what that approach looks like at scale. The defence is unglamorous: verify a recruiter through a channel you chose yourself, never run a technical assessment from an unsolicited archive, and treat any installer that arrives before a contract as hostile. The deeper failure is institutional. Companies still onboard contractors from unverified interviews, and borrowed AI and crypto branding does the rest of the work. Until hiring pipelines confirm who is actually on the call, this number keeps climbing.