NewsTradingSentimentEventsCommunityBriefing
World

North Korean Group Steals $10.7M via Fake Job Campaign

By Geopolitics Desk · · 2 min read
A server rack with blinking status lights in a dark room
Illustration: Tradingbird

A joint advisory reveals that a North Korean cyber group compromised 30,000 devices through fake interviews, stealing millions in crypto.

Key points

  • North Korean actors compromised 30,000 devices in over 100 countries using fake job interviews.
  • The campaign stole $10.71 million in cryptocurrency from over 7,000 wallets.
  • The group is linked to North Korea's IT worker program for identity fraud and espionage.

Cybersecurity agencies from the United States, Japan, Australia, and Germany have issued a joint advisory detailing a sophisticated campaign attributed to North Korean state actors. The group, known under various aliases including WaterPlum and CL-STA-0240, has compromised at least 30,000 devices across more than 100 countries. According to the report, the primary objective was to siphon funds from over 7,000 cryptocurrency wallets, resulting in estimated losses of $10.71 million.

The operation, tracked as the Contagious Interview campaign, targets web designers, engineers, and blockchain specialists. The threat actors pose as recruiters on professional social media platforms, luring victims with lucrative job offers. Once rapport is established, they instruct targets to complete coding assessments, which trigger the deployment of multiple malware families to gain persistent remote access to the victims' networks.

Recruitment Tactics Target Tech Professionals

The campaign has been active since at least 2022, according to The Hacker News. The attackers use social engineering to approach developers on platforms like LinkedIn, presenting themselves as prospective employers. The initial interaction is designed to build trust, leading the victim to believe they are participating in a standard hiring process. This social engineering vector allows the group to bypass traditional perimeter defenses by leveraging the victim’s own device.

The infection chain is complex, involving the delivery of various malware variants such as BeaverTail and GolangGhost. These tools are used to install remote access trojans, enabling the attackers to exfiltrate data and maintain a foothold in the victim's system. The agencies noted that the group uses these backdoors not only for immediate financial theft but also for long-term espionage and lateral movement within corporate environments.

Linkage to State-Run IT Labor

The advisory highlights a deep connection between the cyber intrusions and North Korea’s IT worker program. It is suspected that both the WaterPlum cluster and IT worker groups operate under the 313 General Bureau of the Munitions Industry Department. The agencies stated that these entities are intertwined, sometimes using the same IP addresses to access laptop farms and apply for positions at cryptocurrency exchanges.

Beyond stealing cryptocurrency, the compromised data is used to facilitate identity fraud. Stolen ID images can be utilized by North Korean IT workers to impersonate victims and generate foreign currency. A laptop farm operated by a facilitator in Japan was identified and dismantled, but the agencies warn that the infrastructure remains resilient. The group also uses enablers in the U.S. and Japan to manage remote devices and communicate with targets via online chat platforms.

Broader Implications for Corporate Security

The joint alert emphasizes that successful infections provide opportunities for intellectual property theft and espionage. By infiltrating organizations that employ targeted developers, the attackers can expand their access to critical internal systems. This dual-purpose approach—financial gain and state-sponsored espionage—presents a significant challenge for corporate security teams. The agencies advise organizations to review their hiring processes and monitor for unusual remote access patterns.

As the group continues to evolve, it is increasingly relying on artificial intelligence to craft fictitious identities and expand its global reach. The forward question for the industry is how organizations can better distinguish between legitimate recruitment efforts and state-sponsored phishing campaigns. Vigilance in verifying the authenticity of job offers and securing development environments will be critical in mitigating the risks posed by this persistent threat.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in World

More from the World desk

All desk stories