North Korean Hackers Steal Millions via Fake Job Interviews

A joint international advisory reveals that North Korean cybercriminals compromised 30,000 devices globally by targeting job seekers with fake interviews and malicious code.
Law enforcement agencies in Japan, the United States, Australia, and Germany have released a joint advisory detailing a massive cybercrime operation led by the North Korean group WaterPlum. From December 2025 through July 2026, this group compromised at least 30,000 devices across more than 100 countries. The primary goal was financial, with over $10.7 million in cryptocurrency transferred to North Korea.
The operation, part of a campaign known as Contagious Interview, targeted job seekers by impersonating legitimate tech companies. During simulated interviews and coding tests, victims were tricked into downloading malicious software. This approach allows attackers to bypass traditional security measures by leveraging trust in the hiring process.
Fake Interviews Deliver Malicious Code
The attack method relies on social engineering rather than brute force. Attackers contact candidates on freelance platforms, posing as recruiters for AI or cryptocurrency firms. During video calls, they instruct victims to run specific scripts to troubleshoot technical issues. These scripts install malware such as BeaverTail and InvisibleFerret, which steal credentials, keystrokes, and cryptocurrency keys.
BleepingComputer reports that the malware also captures screenshots and clipboard contents. Once installed, the software allows attackers to pivot into corporate networks, expanding the threat from individual theft to industrial espionage. The use of familiar platforms makes the initial contact seem harmless and professional.
Link to North Korean IT Operations
The advisory connects WaterPlum directly to North Korea’s fraudulent IT worker programs. Some hackers simultaneously work as remote developers for clients, using the same IP addresses for both activities. This dual role facilitates the laundering of stolen funds and provides cover for their espionage operations.
Investigators found that these actors use AI face-swapping software to deceive interviewers. They often turn off their cameras and cite network problems to hide their true location. This deception allows them to maintain a false identity while executing sophisticated attacks from within North Korea.
Recommendations for Protecting Your Systems
Authorities advise companies to rigorously verify the identity and location of remote workers. Access to corporate data should be restricted to only what is necessary for the job. Developers are urged to avoid running unknown code outside of a sandbox environment. This precaution helps prevent the execution of hidden payloads that fetch additional malware.
The trade-off for security is reduced convenience, but the risk of total system compromise is significant. Organizations must balance operational efficiency with strict verification protocols. Ignoring these warnings exposes sensitive data and financial assets to state-sponsored theft.






