North Korean hackers posed as tech employers, ran fake coding interviews, and in some cases used AI face-swapping software to impersonate interviewers before stealing $10.71 million in cryptocurrency from more than 7,000 wallets, according to a joint advisory released September 18 by police and security agencies in Japan, Australia, the United States and Germany.
Fake job scam targets developers through fake interviews
According to the advisory, WaterPlum operators posed as employers, frequently impersonating companies working in artificial intelligence, cryptocurrency and non-fungible tokens.
The attackers approached developers through job platforms and presented coding assessments as part of the recruitment process. Applicants were then instructed to download and execute files from code repositories, allegedly to complete technical assignments or resolve problems affecting video calls.
The files contained npm packages that had been deliberately infected with malware, including BeaverTail, InvisibleFerret and OtterCookie, according to the agencies.
Once the malicious software was installed, it could collect information stored on the victim’s computer. The stolen information reportedly included browser passwords, keystrokes and cryptocurrency wallet seed phrases.
The malware could also collect images of passports and driver’s licences. Authorities said those documents could potentially be used for impersonation or extortion.
The operation therefore went beyond a conventional Fake job scam. By targeting developers with technical assignments, the attackers allegedly used a process that victims would ordinarily expect to involve downloading and running software.
The approach also exploited the trust that can develop during recruitment, particularly when applicants believe they are communicating with a prospective employer or completing a legitimate technical evaluation.
AI deepfakes strengthen the Fake job scam operation
The campaign also incorporated artificial intelligence into some of its interview tactics.
According to the advisory, some members of the group used AI-powered face-swapping software during interviews. The attackers would reportedly appear on camera for several minutes before cutting the video and blaming the interruption on network problems.
They would then ask the applicant to turn off their own camera.
The tactic could make it more difficult for applicants to verify the identity of the person conducting the interview while allowing the attacker to maintain the appearance of a legitimate remote recruitment process.
AI has also surfaced in separate research into suspected North Korean IT workers.
In August, researchers reportedly established a fake decentralized finance startup to observe three suspected North Korean developers. During the operation, the researchers observed the developers using Google’s Gemini to forge documents.
The developments add an artificial-intelligence component to the Fake job scam, with suspected attackers using AI both to facilitate deception and to support fraudulent identities.
University of Melbourne cybersecurity specialist Andrew Cullen told the ABC that reports of fake North Korean employees have circulated for several years.
“I don’t think anybody in the West has a particularly strong grasp on exactly how long this has been happening,” — Andrew Cullen, University of Melbourne cybersecurity specialist.
Cullen said he had seen reports of fake North Korean employees for three to four years.
Japan dismantles North Korean laptop farm
Japanese authorities have also dismantled a laptop farm operated by an alleged enabler in Japan, according to the advisory.
It was described as the first case of its kind in the country. Laptop farms allow North Korean IT workers to remotely control computers used for employment while concealing their actual locations.
The National Police Agency and FBI assess that WaterPlum and some of the IT workers connected to the operation work under North Korea’s 313 General Bureau of the Munitions Industry Department.
The advisory warned that companies that pay North Korean IT workers could potentially violate domestic laws and sanctions.
Leaked records from a North Korean payment system reportedly showed IT workers generating approximately US$1 million per month through false identities earlier this year.
That activity provides another dimension to the Fake job scam problem. Rather than simply targeting victims for one-time payments, fraudulent employment networks can allegedly place North Korean workers inside legitimate companies while using false identities and remote access.
The Japanese laptop-farm case suggests authorities are increasingly examining the infrastructure that enables such workers to operate, rather than focusing solely on individual fraudulent applications.
For cryptocurrency users, the risks can be particularly significant because access to a wallet seed phrase can provide control over digital assets.
Authorities warn against running untrusted code
The joint advisory recommends that developers take precautions when asked to download or execute unfamiliar software during recruitment.
The agencies specifically advise developers to run untrusted code inside a sandbox or virtual machine. Such environments can isolate potentially malicious programs from the computer’s broader files, credentials and applications.
Users who believe their devices have been compromised are advised to move their cryptocurrency assets to a new wallet using a separate device.
The guidance is particularly relevant to a Fake job scam involving software developers because technical recruitment frequently requires candidates to download code, packages and development tools.
A malicious coding assignment can therefore appear indistinguishable from a normal part of the hiring process until the software has already been executed.
The reported theft of US$10.71 million illustrates the financial consequences of the campaign, while the compromise of more than 7,000 crypto wallets indicates the scale described by the authorities.
The broader warning also highlights the continuing use of false employment identities by suspected North Korean operators. The international advisory links the WaterPlum campaign to a wider ecosystem involving malicious software, cryptocurrency theft, remote employment and concealed IT operations.
For developers, the central risk is that a Fake job scam may not initially resemble a conventional cryptocurrency scam. It can instead arrive as a job offer, an interview invitation or a coding assignment from what appears to be a legitimate technology company.
Authorities are therefore urging developers to treat recruitment-related software and code repositories as potentially untrusted until they can be safely verified.
The warning comes as international agencies continue to investigate North Korea-linked cyber operations and the methods used to generate revenue through fraudulent employment and cryptocurrency theft.
In the latest case, the Fake job scam allegedly gave attackers access to both digital assets and sensitive personal information, demonstrating the potential consequences of accepting unfamiliar files as part of an online hiring process.