Fake Recruiters Hit Job Seekers With Malware Files

The Record · High sophistication
Last updated September 21, 2026

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from thousands of cryptocurrency wallets. The same access was also used to potentially “piggyback” into corporate systems if victims later got hired at tech firms.

How the attack worked

The scheme, referred to as WaterPlum, targeted people actively looking for work in AI and blockchain fields. Attackers posed as recruiters for AI or blockchain companies and reached out through social media platforms, gig work websites, and freelance portals. Once contact was established, the fake recruiters moved the conversation into an interview process that required applicants to download and open files, framed as assessments or technical tasks tied to the role.

These files were the actual delivery mechanism for malware. Once opened, the malware infected the applicant's device and harvested cryptocurrency wallet credentials along with other sensitive information. A related pattern was also seen with blockchain developers who were separately contacted by fake recruiters through LinkedIn and asked to run similar malicious file packages.

Why it succeeded

The pretext worked because it mirrored a normal part of many hiring processes: technical assessments, coding tasks, and file-based interview exercises are common in engineering and blockchain roles. Job seekers, especially those actively applying across multiple platforms, are primed to follow instructions from anyone presenting themselves as a legitimate recruiter, and the request to download a file did not stand out as unusual given the target roles.

Reports also describe the use of AI tools during interviews, including face-swapping software, text-to-speech tools with localized pronunciations, and translation tools. This kind of tooling can make a fake interviewer or a foreign-based operator appear more convincing on video calls, reducing the chance that a victim would question the legitimacy of the interaction.

What to watch for

  • Recruiter outreach on social media or freelance/gig portals that quickly moves to requesting a file download or local file execution
  • Interview or assessment steps that bypass standard, verifiable employer platforms
  • Requests tied to handling crypto assets or wallet access on a personal device
  • Urgency or insistence on using the recruiter's own tools instead of company-standard hiring systems

How to build resistance

Organizations and individuals should treat any interview-stage request to download and run files as high risk until the employer and recruiter identity are independently verified. Where possible, technical assessments should be reviewed through sandboxed or view-only methods rather than direct execution on a personal device.

Because attackers in this case reportedly sought to maintain access to a compromised personal device in hopes the victim would later be hired at a tech firm, it's worth reinforcing separation between personal job-search activity and any device or account with corporate access. Hiring teams and security awareness programs should also account for AI-enabled identity deception, including face-swapping and voice tools, when designing interview verification steps for remote candidates.

Key findings

  • Authorities say more than $10.5M was stolen by targeting job seekers and their crypto wallets.
  • Between Dec 2025 and Jul 2026, the campaign allegedly infected at least 30,000 devices across 100 countries and impacted about 7,000 crypto wallets.
  • Victims were approached on social platforms and freelance/gig portals and instructed to download files as part of the interview process.
  • The operation also sought longer-term access: keeping persistence on victims’ devices to later gain entry to corporate environments if victims were hired.
  • Japanese officials reported disrupting a “laptop farm” and found indicators of AI-assisted interviewing (face swapping, text-to-speech, translation tools).

Who’s being targeted

  • Commonly targeted roles: HR / Talent Acquisition, Hiring Managers, Engineering, Web Developers / Designers, Blockchain / Crypto teams, IT / Security, Employees job-searching on the side (general workforce awareness).
  • Affected industries: Technology, Cryptocurrency / Blockchain, Software development, Defense (historical targeting mentioned), Media and online services (historical targeting mentioned).
  • Attack channels: linkedin.
  • Impersonated: AI or blockchain company recruiter, Recruiter (fake) for blockchain developer roles.

Red flags to watch for

  • Recruiter requires downloading files/software early in the hiring process
  • Contact comes via social media/freelance portals with limited verifiable company presence
  • Unusual urgency or insistence on using their provided files/tools instead of standard hiring platforms
  • Unsolicited recruiter outreach with a request to run files locally
  • Hiring workflow that bypasses normal employer verification steps
  • Request is tied to handling crypto assets or “wallet” access on a personal device
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake recruiter scheme target job seekers?

Victims were contacted through social media platforms, gig work websites and freelance portals by attackers posing as AI or blockchain companies, then instructed to download files as part of the interview process.

What happened after victims downloaded the files?

The files infected devices and allowed attackers to steal cryptocurrency wallet credentials and other information from applicants.

Could this scheme affect a company beyond the job seeker?

Yes, the attackers reportedly maintained access to victim devices hoping the person would later get hired at a tech firm, potentially allowing them to piggyback into corporate systems.

What AI tools were used to make the interviews seem legitimate?

Reports describe use of AI face-swapping software, text-to-speech tools with localized pronunciations, and AI translation tools during interviews.

Read the video transcript

You get a LinkedIn message: “We love your profile for a blockchain role. Just download this assessment before the interview.” Sounds legit, right? This is the WaterPlum scam. Fake AI and blockchain recruiters get you to run their files, then quietly drain your crypto wallets and keep a backdoor on your laptop, over $10 million stolen from job seekers this way. Here’s the nasty twist: they keep that access. If you later join a tech company and use the same laptop, WaterPlum can ride your device straight into our corporate network, months after the fake interview. Your move: if any recruiter asks you to download or run files for an interview, stop and verify the company through its official website and our security team before you open anything, every time.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Iranian Spies Lure Targets via WhatsApp to Drop Malware

Iranian Spies Lure Targets via WhatsApp to Drop Malware

A joint UK-US-Dutch advisory warns Iranian state-backed cyber actors are targeting dissidents, activists, and journalists by first contacting them on WhatsApp or Telegram and building trust. The attackers then persuade victims to open a malicious file disguised as legitimate software (or even MRI…

September 16, 2026
Fake MRI File Used to Deliver Iran Spyware

Fake MRI File Used to Deliver Iran Spyware

UK, US, and Dutch agencies warned that Iran-linked operators used long-running social engineering to build trust with targets (including dissidents, activists, and journalists), then sent malicious files disguised as legitimate documents or software installers. One lure included a fake MRI scan…

September 15, 2026
Crypto Scammers Posed as Apple/Google Support

Crypto Scammers Posed as Apple/Google Support

U.S. prosecutors say a group led by Malone Lam ran social engineering scams that stole over $245 million in cryptocurrency. The scammers allegedly called crypto holders while pretending to be customer support from Apple or Google, talked victims into handing over key account details, and in at…

September 8, 2026