Fake AI Recruiters Hit 30K Devices Worldwide

Check Point Research · High sophistication
Last updated September 22, 2026

A weekly threat bulletin highlights a North Korea–linked campaign where attackers posed as AI or blockchain employers to trick IT professionals into getting infected and losing cryptocurrency. It also notes a phishing kit that abuses Microsoft’s legitimate device login flow to gain long-lasting access to Microsoft 365 accounts without directly stealing passwords.

How the attack worked

This campaign, tracked as WaterPlum or "Contagious Interview," relied on attackers posing as AI or blockchain employers to reach IT professionals, developers, and blockchain engineers. The pretext was simple and effective: a recruiter reaches out on a platform like LinkedIn, offers an interview for an AI or blockchain role, and asks the target to complete a task as part of the process. That task becomes the delivery mechanism for infection. According to the findings, this approach infected at least 30,000 devices across more than 100 countries, with theft impacting over 7,000 cryptocurrency wallets between December 2025 and July 2026.

A separate technique described in the same bulletin involves GhostCode, a phishing kit that abuses the legitimate OAuth 2.0 device authorization flow used by Microsoft 365. Instead of stealing a password directly, the kit tricks victims into authenticating through a real Microsoft sign-in page using a device code. Attackers then capture the resulting tokens, giving them persistent account access without needing the password or bypassing MFA outright.

Why it succeeded

Both techniques work because they exploit trust in legitimate-looking processes rather than obviously malicious ones. A job interview is a normal, expected interaction for IT professionals and developers, so a request to complete a technical task does not raise immediate suspicion. Similarly, the device-code flow is a real Microsoft feature, so victims who are asked to enter a code are following what looks like a standard sign-in step, not a fake login page.

What to watch for

  • Unsolicited recruiter messages, especially for AI or blockchain roles, that push toward downloading files or running interview "tasks"
  • Requests to enter or use a Microsoft device code when you did not initiate a sign-in on another device yourself
  • Employer or recruiter profiles that are difficult to verify independently, such as new accounts with limited online history
  • Pressure to act quickly to "verify" or "fix" account access tied to a login request

How to build resistance

Organizations should train IT staff, developers, and crypto or finance teams to verify recruiter and employer identities independently before engaging with interview materials or running provided code. Employees across the organization, including executives and HR, should be taught to treat any unexpected device-code sign-in request as suspicious, since MFA alone does not stop token capture. Building awareness around both the recruiter pretext and the device-code flow reduces the chance that either technique succeeds against a given target.

Key findings

  • Authorities warned about WaterPlum ("Contagious Interview"), a North Korea-linked campaign that "infected at least 30,000 devices across more than 100 countries."
  • WaterPlum operators "posed as AI or blockchain employers" and targeted "IT professionals," with theft impacting "over 7,000 cryptocurrency wallets" (Dec 2025–Jul 2026).
  • A device-code phishing kit (GhostCode) abuses the "legitimate OAuth 2.0 device authorization flow" so victims authenticate through Microsoft and attackers capture tokens for persistent access.

Who’s being targeted

  • Commonly targeted roles: IT, Developers/Engineering, All Microsoft 365 users, Executives, Finance/Crypto teams.
  • Affected industries: Information Technology, Cryptocurrency/Web3, Government.
  • Attack channels: linkedin, email, website.
  • Impersonated: AI or blockchain employer/recruiter, Microsoft / Microsoft 365 sign-in.

Red flags to watch for

  • Unsolicited recruiting message with urgency to move off-platform or run files
  • Interview ‘task’ requires downloading/running software or enabling macros
  • Employer identity is hard to verify (new profile, limited web presence)
  • You are asked to use a ‘device code’ when you weren’t trying to sign in on another device
  • Login is initiated from a link you received unexpectedly
  • Message pressures you to act quickly to ‘verify’ or ‘fix’ account access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Contagious Interview campaign?

It is a North Korea linked campaign called WaterPlum that posed as AI or blockchain employers to target IT professionals, infecting at least 30,000 devices across more than 100 countries.

How did attackers steal cryptocurrency in this campaign?

By posing as employers and engaging IT professionals in a fake interview process, attackers gained access that led to theft impacting over 7,000 cryptocurrency wallets.

What is device-code phishing and why is it dangerous?

It is a technique where a phishing kit called GhostCode abuses the legitimate OAuth 2.0 device authorization flow so victims authenticate through Microsoft while attackers capture tokens, gaining persistent account access without stealing a password or directly bypassing MFA.

Does MFA protect against this type of attack?

Not fully. Since token-based device-code attacks capture access tokens rather than passwords, users must avoid approving unexpected sign-in requests even if MFA is enabled.

Read the video transcript

Imagine a LinkedIn recruiter for an AI or blockchain role… and that “interview” quietly infects your laptop. WaterPlum, also called Contagious Interview, posed as AI or blockchain employers, hit at least 30,000 devices, and drained over 7,000 crypto wallets when IT pros ran “interview tasks.” Now add GhostCode: an email says, “Use this Microsoft device code to sign in and complete verification.” You really log in to Microsoft, but they capture tokens and keep Microsoft 365 access without your password or even breaking MFA. Your move: if a recruiter wants you to run files, or an email pushes a Microsoft device code you didn’t start, stop and verify the company or sign-in using your own browser, not their link.

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Consent Phishing and Hijacked Hotel Wi‑Fi Portals

Consent Phishing and Hijacked Hotel Wi‑Fi Portals

This weekly threat bulletin summarizes multiple real-world incidents, including phishing that abuses Microsoft’s legitimate app login/consent screens and a campaign that hijacks hotel Wi‑Fi captive portals. In both cases, the goal is to trick people into granting access or capturing Microsoft…

August 3, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026