North Korean Hackers Use Job Postings to Steal Crypto, Data
North Korean hackers have been using job postings as a ruse to gain access to computer networks of tens of thousands of job seekers worldwide, warns an international alert from security agencies. The group, known as WaterPlum or Contagious Interview, poses as prospective employers, such as artificial intelligence firms, to target software developers and IT professionals.
The agencies attribute the group to operating under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers Party of Korea. The efforts are linked to North Korean IT workers, with some WaterPlum actors even operating as North Korean IT workers performing web system design and development tasks for clients.
The stolen information has been used to fuel other operations, with a substantial overlap between WaterPlum and North Korean IT workers. The agencies report that WaterPlum has infected more than 30,000 devices in over 100 countries, targeting IT professionals in Japan, the US, Europe, and other nations.
The group's operations have transferred nearly $11 million worth of cryptocurrency from over 7,000 crypto wallets to North Korea. The law enforcement agencies have had some success tackling the group but are seeking further cooperation and released details about WaterPlum's tactics, techniques, and procedures in the alert.