$ techbeacon▋
Threats

North Korean ‘WaterPlum’ Campaign Uses Bogus Tech Interviews to Compromise Thousands of IT Workers

North Korean ‘WaterPlum’ Campaign Uses Bogus Tech Interviews to Compromise Thousands of IT Workers

Cybersecurity researchers have identified a new intrusion effort attributed to a North Korean group known as WaterPlum, or Contagious Interview, that has compromised roughly 30,000 computers across more than 100 nations. The operation hinges on a deceptive recruitment tactic: promising software developers and other IT professionals a “job interview” that, in reality, serves as a conduit for malicious code.

Victims are contacted through professional networking sites or direct email, where they receive an invitation to a video call or a questionnaire that appears to be part of a legitimate hiring process. When the target clicks a link or downloads a file purportedly containing interview materials, a custom payload is installed. The malware creates a foothold on the device, then silently harvests cryptocurrency wallet credentials and private keys, funneling the stolen assets to addresses linked to the North Korean regime.

The scale of the campaign is notable. Analysts estimate that at least 30,000 endpoints have been infected, spanning industries from web development firms to cloud‑service providers. While the primary motive appears to be financial—exfiltrating crypto holdings to fund the country’s sanctioned activities—the attackers also gain access to valuable source code and internal tools that could be leveraged for future espionage or sabotage.

WaterPlum is not the first North Korean cyber unit to blend financial crime with state‑aligned objectives. The nation’s hacking groups have a history of exploiting the anonymity of digital currencies, from the 2017 WannaCry ransomware outbreak to more recent cryptojacking campaigns. By masquerading as recruiters, the actors avoid the typical phishing hooks that many security filters block, making the scheme harder to detect until the malware is already active.

Security firms are urging organizations to educate their technical staff about the risks of unsolicited interview requests and to enforce strict verification procedures for any recruitment outreach. Multi‑factor authentication, network segmentation, and regular monitoring of cryptocurrency transaction logs are recommended defenses. As the WaterPlum operation continues to evolve, experts warn that similar social‑engineering lures could appear in other professional domains, underscoring the need for heightened vigilance across the tech workforce.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related