Fake Job Interviews and Linux Espionage Toolkit Mark North Korean Cyber Ops
Recent advisories highlight two distinct North Korean operations: crypto theft via fake recruiting and espionage via a new Linux toolkit.
Two sources describe a North Korean campaign known as WaterPlum. Recruiters posed as AI or blockchain employers and sent coding tests that installed backdoors on jobseekers' machines. The Register puts the infection count at 30,000 devices and says the actors drained more than 7,000 crypto wallets; Recorded Future News reports the campaign reached over 100 countries and cites a joint advisory from the FBI, the US Department of Defense, Japan's National Police Agency, and agencies in Australia and Germany.
The two accounts agree on the core tactics and impact, though The Register offers the specific device and wallet figures while Recorded Future News stresses the international scope. Neither article links WaterPlum to other North Korean activity.
A third source, Dark Reading, covers a different likely North Korean APT operation targeting South Korean media and automotive sectors. That campaign used an undocumented Linux espionage toolkit to compromise load balancers and intercept communications. The sources describe separate efforts rather than one unified campaign.
Sources · 7
- Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- North Korea’s job interview scam runs both ways
- North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs
- North Korean WaterPlum hackers infected 30,000 devices worldwide
- North Korea's fake job interviews infected 30,000 devices
- North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
- Cyber Op Targets South Korean Media & Automotive Sectors
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.