Australian and allied agencies warned that North Korean-linked actors are impersonating recruiters and fake AI/crypto/NFT companies to lure IT professionals into a hiring process that installs malware. The goal is to steal sensitive information and drain cryptocurrency wallets, with reporting claiming tens of thousands of infections across many countries.
How the Attack Worked
North Korean linked actors, tracked as WaterPlum or Contagious Interview, have been posing as recruiters and as fake AI, cryptocurrency, and NFT companies to reach IT professionals worldwide. The outreach is sometimes routed through recruiting services to appear more legitimate. Once a target engages with the fake hiring process, the actors work to compromise the victim's device with malware, aiming to harvest sensitive information and steal cryptocurrency. A related pattern involves DPRK nationals using stolen or fabricated identities, including forged passport data, to actually get hired by companies that have no idea who they employed.
Why It Succeeded
The lure leans on themes that are currently in high demand: AI, cryptocurrency, and NFTs. This makes an unsolicited recruiter message feel timely rather than suspicious, especially to IT and engineering professionals who may be actively looking for new opportunities in these fields. Routing outreach through recruiting services adds a layer of perceived legitimacy, making it harder for targets to independently verify who they are actually talking to. On the hiring side, identity verification gaps allowed fabricated documents to pass through onboarding processes undetected.
What to Watch For
- Unsolicited recruiter contact for a high paying role tied to AI, crypto, or NFT companies
- Pressure to follow a specific hiring process that requires opening files or running steps on your own device
- A recruiter or company identity that is difficult to verify, especially when routed through an unfamiliar recruiting service
- Job candidates who resist live identity verification or submit inconsistent identity documents
- Any hiring workflow request that leads to installing software before an official offer is made
How to Build Resistance
Organizations should treat unsolicited recruiter outreach, particularly for trendy AI or crypto roles, as something that requires independent verification of both the recruiter and the company before any engagement continues. IT staff and security engineers should be trained never to run interview files, setup tools, or unfamiliar steps from an unverified hiring process, and to escalate suspicious recruiting interactions to security teams. HR and hiring teams should strengthen identity checks for remote IT hiring, including live verification and document validation, escalating when passports or other identification look unusual. Because cryptocurrency theft is a stated objective, organizations that handle crypto assets should apply extra scrutiny to job related outreach and hiring workflows overall.
Key findings
- North Korean cyber actors (WaterPlum/Contagious Interview) are posing as recruiters and companies to target IT professionals worldwide.
- The lure is a fake job opportunity (often themed around AI, cryptocurrency, and NFTs), sometimes routed through recruiting services.
- After engagement, victims are pushed through a fake hiring process that results in malware infection to steal data and cryptocurrency.
- The advisory claims more than 30,000 devices infected in over 100 countries, with thousands of wallets drained.
- Separately, reporting describes DPRK nationals using stolen/fabricated identities to get hired, including sharing forged passport data and bypassing identity checks.
Who’s being targeted
- Commonly targeted roles: IT and engineering staff, Security team, HR / Recruiting, Hiring managers, Crypto/finance operations (if applicable).
- Affected industries: Technology / IT services, Crypto / Web3 companies, Recruiting and staffing, Any organization hiring remote IT talent.
- Attack channels: email.
- Impersonated: External recruiter / hiring team for an AI, cryptocurrency, or NFT company, Job candidate using a stolen or fabricated identity.
Red flags to watch for
- Unsolicited recruiter approach for a trendy/high-pay domain (AI/crypto/NFT)
- Pressure to follow a specific ‘hiring process’ that requires opening files or running steps on your device
- Recruiter/company identity is hard to verify or routed through an opaque recruiting service
- Identity documents appear inconsistent or come from unexpected countries
- Candidate resists live identity verification steps
- Unusual reliance on scanned/forged passport data
Frequently asked questions
Who is behind these fake recruiter attacks?
Advisories attribute the activity to North Korean-linked actors tracked as WaterPlum, also known as Contagious Interview, who pose as recruiters and fake AI, cryptocurrency, and NFT companies.
How does the fake job scam actually infect a victim?
Once a target engages with the fake hiring process, the actors work to compromise the target's device with malware to harvest sensitive information and steal cryptocurrency.
Is this only a risk for individual job seekers?
No. Reporting also describes DPRK nationals using stolen or fabricated identities to get hired as employees, meaning hiring and HR teams face a separate insider-by-hire risk.
What roles are most targeted?
IT professionals, software developers, DevOps and cloud engineers, and security engineers are named as primary targets, along with HR and hiring managers involved in recruitment workflows.
Read the video transcript
You get an email: “Hi, I’m reaching out about a role with an AI/crypto company. Open to a quick chat?” Sounds flattering, right? Australian agencies say a group called WaterPlum, also known as Contagious Interview, uses fake AI, crypto, and NFT companies to run a bogus hiring process that quietly installs malware and drains crypto wallets, over 30,000 devices hit in 100+ countries. Here’s the trick: after a few friendly messages, the ‘recruiter’ insists you follow their exact hiring steps, opening attachments or running an “interview tool” on your own machine from a company you can’t really verify. If a recruiter you didn’t seek out wants you to open files or run tools, stop. Don’t run anything, forward it to security and independently look up the company before you take another step.