North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide

North Korean hackers posing as recruiters have compromised tens of thousands of computers used by software developers and other technology workers, a multinational cyber‑security warning said Friday. The advisory cautioned that seemingly innocuous coding tasks and fixes for video‑conferencing tools can open a backdoor to both personal devices and corporate networks.
Malicious Coding Assignments
The joint alert, released by authorities in Japan, Australia, Germany and the United States, highlighted that the threat actors disguise malicious code as legitimate development work or as patches for remote‑meeting software. By exploiting this trust, the group gains footholds inside the victim’s workstation and can later move laterally across the employer’s internal systems.
30,000 Devices Infected
According to the Federal Bureau of Investigation and the Department of Defense’s Cyber Crime Center, the North Korean group identified as WaterPlum – also referred to as Contagious Interview – succeeded in infiltrating at least 30,000 devices worldwide. The campaign targeted individuals who write software, as well as broader IT professionals, during a window that stretched from December 2025 through July 2026.
Nearly $11 Million Sent
Investigators traced the illicit activity to more than 7,000 cryptocurrency wallets whose funds or login credentials were harvested by the hackers. The stolen assets were then funneled to accounts linked to North Korea, amounting to roughly 1.7 billion Japanese yen, which translates to about $10.7 million, and bringing the total value of cryptocurrency transferred to the regime close to $11 million.
Active since 2023
Officials noted that WaterPlum has been operating since 2023, blending financially driven theft with cyber‑espionage missions. The dual focus reflects a broader pattern among state‑aligned hacking groups that seek both revenue streams and intelligence gains. While the advisory emphasized the immediate financial loss, it also warned of the longer‑term risk that compromised devices pose to corporate intellectual property and national security.
The multinational warning urged developers and their employers to verify the provenance of any code or software update before execution. It recommended employing multi‑factor authentication, regularly updating security patches, and monitoring cryptocurrency transaction logs for anomalous activity. By tightening these defenses, organizations can reduce the chance that a seemingly routine development request becomes a conduit for a state‑sponsored intrusion.
Source: inc.com · 2026-09-20