DPRK Poses as Recruiters to Malware IT Pros

IT News Australia · High sophistication
Last updated September 22, 2026

Australian and allied agencies warned that North Korean-linked actors are impersonating recruiters and fake AI/crypto/NFT companies to lure IT professionals into a hiring process that installs malware. The goal is to steal sensitive information and drain cryptocurrency wallets, with reporting claiming tens of thousands of infections across many countries.

How the Attack Worked

North Korean linked actors, tracked as WaterPlum or Contagious Interview, have been posing as recruiters and as fake AI, cryptocurrency, and NFT companies to reach IT professionals worldwide. The outreach is sometimes routed through recruiting services to appear more legitimate. Once a target engages with the fake hiring process, the actors work to compromise the victim's device with malware, aiming to harvest sensitive information and steal cryptocurrency. A related pattern involves DPRK nationals using stolen or fabricated identities, including forged passport data, to actually get hired by companies that have no idea who they employed.

Why It Succeeded

The lure leans on themes that are currently in high demand: AI, cryptocurrency, and NFTs. This makes an unsolicited recruiter message feel timely rather than suspicious, especially to IT and engineering professionals who may be actively looking for new opportunities in these fields. Routing outreach through recruiting services adds a layer of perceived legitimacy, making it harder for targets to independently verify who they are actually talking to. On the hiring side, identity verification gaps allowed fabricated documents to pass through onboarding processes undetected.

What to Watch For

  • Unsolicited recruiter contact for a high paying role tied to AI, crypto, or NFT companies
  • Pressure to follow a specific hiring process that requires opening files or running steps on your own device
  • A recruiter or company identity that is difficult to verify, especially when routed through an unfamiliar recruiting service
  • Job candidates who resist live identity verification or submit inconsistent identity documents
  • Any hiring workflow request that leads to installing software before an official offer is made

How to Build Resistance

Organizations should treat unsolicited recruiter outreach, particularly for trendy AI or crypto roles, as something that requires independent verification of both the recruiter and the company before any engagement continues. IT staff and security engineers should be trained never to run interview files, setup tools, or unfamiliar steps from an unverified hiring process, and to escalate suspicious recruiting interactions to security teams. HR and hiring teams should strengthen identity checks for remote IT hiring, including live verification and document validation, escalating when passports or other identification look unusual. Because cryptocurrency theft is a stated objective, organizations that handle crypto assets should apply extra scrutiny to job related outreach and hiring workflows overall.

Key findings

  • North Korean cyber actors (WaterPlum/Contagious Interview) are posing as recruiters and companies to target IT professionals worldwide.
  • The lure is a fake job opportunity (often themed around AI, cryptocurrency, and NFTs), sometimes routed through recruiting services.
  • After engagement, victims are pushed through a fake hiring process that results in malware infection to steal data and cryptocurrency.
  • The advisory claims more than 30,000 devices infected in over 100 countries, with thousands of wallets drained.
  • Separately, reporting describes DPRK nationals using stolen/fabricated identities to get hired, including sharing forged passport data and bypassing identity checks.

Who’s being targeted

  • Commonly targeted roles: IT and engineering staff, Security team, HR / Recruiting, Hiring managers, Crypto/finance operations (if applicable).
  • Affected industries: Technology / IT services, Crypto / Web3 companies, Recruiting and staffing, Any organization hiring remote IT talent.
  • Attack channels: email.
  • Impersonated: External recruiter / hiring team for an AI, cryptocurrency, or NFT company, Job candidate using a stolen or fabricated identity.

Red flags to watch for

  • Unsolicited recruiter approach for a trendy/high-pay domain (AI/crypto/NFT)
  • Pressure to follow a specific ‘hiring process’ that requires opening files or running steps on your device
  • Recruiter/company identity is hard to verify or routed through an opaque recruiting service
  • Identity documents appear inconsistent or come from unexpected countries
  • Candidate resists live identity verification steps
  • Unusual reliance on scanned/forged passport data
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Who is behind these fake recruiter attacks?

Advisories attribute the activity to North Korean-linked actors tracked as WaterPlum, also known as Contagious Interview, who pose as recruiters and fake AI, cryptocurrency, and NFT companies.

How does the fake job scam actually infect a victim?

Once a target engages with the fake hiring process, the actors work to compromise the target's device with malware to harvest sensitive information and steal cryptocurrency.

Is this only a risk for individual job seekers?

No. Reporting also describes DPRK nationals using stolen or fabricated identities to get hired as employees, meaning hiring and HR teams face a separate insider-by-hire risk.

What roles are most targeted?

IT professionals, software developers, DevOps and cloud engineers, and security engineers are named as primary targets, along with HR and hiring managers involved in recruitment workflows.

Read the video transcript

You get an email: “Hi, I’m reaching out about a role with an AI/crypto company. Open to a quick chat?” Sounds flattering, right? Australian agencies say a group called WaterPlum, also known as Contagious Interview, uses fake AI, crypto, and NFT companies to run a bogus hiring process that quietly installs malware and drains crypto wallets, over 30,000 devices hit in 100+ countries. Here’s the trick: after a few friendly messages, the ‘recruiter’ insists you follow their exact hiring steps, opening attachments or running an “interview tool” on your own machine from a company you can’t really verify. If a recruiter you didn’t seek out wants you to open files or run tools, stop. Don’t run anything, forward it to security and independently look up the company before you take another step.

Similar attacks

Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026