North Korean Hackers Scam IT Job Seekers, Steal Rs 100 Crore

The CSR Journal Magazine

North Korean hackers have successfully executed a scam targeting thousands of IT job seekers across more than 100 countries, reportedly stealing around Rs 100 crore. This information has emerged from a joint advisory issued by authorities in Japan, the United States, Australia, and Germany. The hacking group, known as WaterPlum, also referred to as Contagious Interview, allegedly portrayed themselves as job recruiters to deceive their victims.

The fraudulent activities primarily took place between December 2025 and July 2026. During this timeframe, the group purportedly accessed financial and account information from more than 7,000 cryptocurrency wallets, transferring approximately 1.7 billion Japanese yen, which equates to roughly Rs 100 crore, to North Korea. This operation is believed to have commenced in 2023, with the group undertaking both financially motivated attacks and cyberespionage.

The advisory has outlined that WaterPlum approached potential candidates via various online platforms, including social media and freelance marketplaces. Presenting as recruiters or employees from AI or cryptocurrency firms, they enticed individuals with promising job opportunities, ultimately leading to malicious activities.

How the Hackers Executed Their Scheme

Authorities have detailed the methods employed by WaterPlum to carry out the scam against job seekers. Targeted individuals were often requested to participate in virtual technical interviews or complete coding assessments. During these sessions, they were persuaded to download specific files under the pretext of verifying their technical skills or addressing supposed technical issues with video conferencing.

Once the candidates executed the downloads, malware was deployed, enabling the hackers to maintain control of the victim’s device and extract sensitive data. The information compromised included login credentials for browsers, passwords, screenshots, clipboard data, and even documents such as driving licences and passports. The advisory highlighted various malware families associated with these incidents, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

Moreover, the ramifications of these attacks extended beyond individual victims. If a compromised device belonged to a developer working for a company, the hackers could potentially exploit that access to infiltrate the employer’s network, posing a significant threat to source code, credentials, and sensitive information.” The potential for further espionage or theft of intellectual property was noted as an alarming consequence.

Connection to North Korean IT Workers

The advisory further indicates a connection between WaterPlum’s operations and a separate scheme involving North Korean IT workers who concealed their identities to secure remote employment with foreign companies. Investigators noted that both groups used the same IP addresses while utilising crowdsourcing platforms and applying for job roles, including those submitted to a Japanese cryptocurrency exchange.

Notably, Japanese authorities revealed that they had identified and dismantled a laptop farm, a setup designed to obscure the true location of operators. North Korean IT workers allegedly utilised false identity images to impersonate legitimate professionals and secure contracts, with payments often made through third-party accounts or cryptocurrencies.

In multiple instances, these workers engaged in further malicious actions. For example, one individual reportedly extorted a company over payments and leaked its proprietary source code online, while another defaced a company’s website, rendering it inaccessible. In May 2025, a suspect believed to be a North Korean IT worker applied for a position at a Japanese cryptocurrency exchange but was rejected after inconsistencies in language proficiency were detected.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos