A North Korean operation tracked as WaterPlum has used fake job interviews to plant malware on roughly 30,000 devices, stealing $10.7 million in cryptocurrency and leaving persistent remote access trojans behind on the machines it touched.

The delivery mechanism is a coding test. A recruiter approaches a developer with an attractive opening, sends a take-home assignment or a technical exercise, and the assignment carries a payload. The developer runs it, because running the assignment is the entire point of the assignment.

The compromise outlives the interview

What makes this more than a crypto theft is the persistence. The trojans stay usable months after the interview ends. The machine they sit on is very often the same laptop the developer will be using at whatever job they actually take, which turns a failed application into a foothold inside a company that never met the attacker.

That is a supply chain attack routed through a person's career. The victim has no relationship with the eventual target, the eventual target has no visibility into how the laptop was compromised, and the gap between infection and use can be long enough that nobody connects the two.

The operation also harvests credentials and personal data, which feeds the other half of the programme. North Korea runs fake IT workers inside legitimate Western companies, an effort that international agencies estimate brings in around $500 million a year, and stolen identities are the raw material for those applications. Amazon has blocked more than 1,800 suspected North Korean applications since April 2024, with a cluster of examples in late 2025.

Where the fake recruiters operate

The targeting is specific. As Tom's Hardware summarised the agency advisories, the recruiters go after software developers and IT professionals, borrow the names of real AI, cryptocurrency and NFT companies, and post through mainstream job platforms, social media, gig work sites and freelance marketplaces.

Those are not obscure channels. A listing on a well-known job board carrying the name of a funded startup clears most of the checks a candidate would think to run, and the industry has trained developers to expect exactly this workflow. Take-home assignments, unfamiliar repositories, dependencies installed without reading them, a build script run on a personal machine: that is a normal Tuesday in hiring, and it is indistinguishable from the attack.

Sanctions explain the persistence of the effort. Excluded from most of the international economy, the state has turned revenue generation into a technical discipline, and the same infrastructure that steals a wallet also builds a résumé.

What actually helps

Companies have started defending against the fake-worker side, with identity verification and interview controls. Individuals looking for work have less to draw on, which is where the practical advice sits.

Apply through the company directly rather than following a recruiter's link, and if an opening looks plausible but unfamiliar, contact the company to confirm it exists. When a technical assignment does arrive, run it in a throwaway virtual machine rather than on the laptop that holds your keys, your browser sessions and your next employer's VPN profile. That one habit breaks the entire chain, because the value of this attack is not the code the developer writes. It is the machine the developer carries.

The broader lesson is the same one organisations keep relearning as software gets easier to run and harder to account for. Cisco has found unsanctioned AI agents already operating on most of the networks it inspects, and credential theft is now the common entry point rather than the exotic one. The perimeter that matters is not the office network. It is whatever hardware the person joining next week has been running code on for the past six months, and nobody is auditing that either.