North Korean hackers steal $10M in crypto via fake jobs

North Korean cybercriminals are employing phony job opportunities to breach the systems of technology workers, pilfer digital currencies, and gather data for subsequent operations. Over 30,000 devices and 7,000 cryptocurrency wallets have been compromised, generating at least $10.71 million for the attackers, according to authorities in Australia, Germany, Japan, and the United States.
How the scheme works
The group, referred to as WaterPlum, targets web designers, software engineers, and individuals working in cryptocurrency and Web3. They pose as recruiters and send victims what appears to be a coding exercise or technical test as part of the hiring process. These files contain malware that, once downloaded and opened, allows attackers to install remote-access tools and information stealers on the victim’s computer.
The malware collects sensitive data, including login credentials, clipboard data, keystrokes, cryptocurrency wallet information, identity documents, and proprietary files. This not only puts the victim at risk but also their employer if the compromised computer is used for legitimate work.
Wider implications and North Korea’s IT workforce
Stolen identity documents may help North Korean IT workers conceal their identities when seeking jobs abroad, allowing them to generate foreign currency. The campaign is part of a larger North Korean effort to earn money through remote IT work, with an estimated 100,000 North Korean IT workers employed or seeking work globally, potentially bringing in over $500 million annually for North Korea.
Read Also: Putin’s voting demo shows unactivated Windows on Dell
Potential uses of stolen credentials and sensitive data
Stolen identity documents enable North Korean IT workers to impersonate victims, securing jobs abroad and generating foreign currency. The attackers can exploit stolen credentials to steal cryptocurrency, access personal data, or obtain trade secrets from employers, clients, and contractors.
Identifying and addressing fraudulent activity
Companies are becoming more aware of signs that a job candidate may be using a false identity. Red flags include impressive résumés that don’t match interview performance, reluctance to meet in person, technical issues during video calls, and requests for cryptocurrency payments. North Korean workers may also use AI face-swapping tools during interviews, which can leave visual glitches or cause candidates to turn off their cameras abruptly.
Authorities recommend that companies suspecting they’ve hired a fraudulent North Korean IT worker conduct a full forensic investigation, assuming that passwords, systems, and sensitive data may have been compromised.
