Skip to content
Back to Guavy Wire
Crypto

North Korean Hackers Target Job Seekers with Fake Recruiter Scam

Share

A North Korean hacking group called WaterPlum has compromised over 30,000 devices in more than 100 countries, according to a joint advisory from Japanese, US, Australian, and German authorities. The group, also known as Contagious Interview, targets software developers and IT professionals worldwide by posing as recruiters offering attractive job opportunities.

WaterPlum's scam involves fake interviews and requests for job seekers to download and run malicious files hosted on developer platforms and code repositories. During the interviews, the hackers instruct victims to complete a coding assignment or troubleshoot a video conferencing issue, which allows them to install malware and exfiltrate sensitive data and cryptocurrency.

The stolen data can include login credentials, clipboard information, keylogs, screenshots, and files stored on a PC or in shared folders. The advisory warns that the actors can use this stolen sensitive information for extortion. At least $10.71 million has been stolen through this scheme and transferred to North Korea.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc