Australia Warns Fake Job Scam by North Korean Hackers Has Stolen $10.7M in Crypto
- ASD’s Australian Cyber Security Centre co-signed a 18 September advisory, led by Japan’s National Police Agency, on the North Korean group WaterPlum.
- The agencies say WaterPlum infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.
- The group took funds or credentials from over 7,000 crypto wallets and moved US$10.71 million (AU$15.3 million) to North Korea, the advisory states.
Australia’s cyber agency and its Japanese, US and German counterparts warned that North Korean hackers posing as recruiters have stolen US$10.71 million (AU$15.3 million) in crypto.
Japan’s National Police Agency led the joint advisory, which names the group WaterPlum. The Australian Cyber Security Centre co-signed the advisory with the FBI, the US Defense Department’s Cyber Crime Center and Germany’s BND and BfV.
From around December 2025 to July 2026, WaterPlum infected at least 30,000 computers in more than 100 countries, the agencies said. It took funds or account credentials from over 7,000 crypto wallets.
Read more: Michael Saylor Calls for a “Bill of Digital Rights” to Protect Crypto Freedoms
How the Fake Interviews Work
WaterPlum’s members pose as employers, often impersonating AI, crypto or NFT companies. They recruit developers on job sites, then set coding tests.
During interviews, candidates are told to download and run files from code repositories to finish an assignment or fix a video-call error. Those files include npm packages the actors laced with malware such as BeaverTail, InvisibleFerret and OtterCookie, the advisory says.
Once installed, the malware lifts saved browser passwords, keystrokes and wallet seed phrases. It also takes licence and passport images, which the agencies say can be used for impersonation or extortion.
Some members ran those interviews through AI face-swapping software. They cut their video after a few minutes, blamed network issues and asked targets to switch off theirs too.
AI tools turned up again in August, when researchers ran a fake DeFi startup to watch three suspected North Korean developers and watched them forge documents with Google’s Gemini.
Laptop Farm Dismantled in Japan
Japanese authorities dismantled a laptop farm run by an enabler in Japan, the first such case in the country. Laptop farms host work computers that North Korean IT workers control remotely.
The NPA and the FBI assess that WaterPlum and some of those IT workers operate under North Korea’s 313 General Bureau of the Munitions Industry Department. Paying North Korean IT workers may breach domestic law and sanctions, the advisory warns.
Leaked records from one North Korean payment system showed IT workers earning about US$1 million (AU$1.43 million) a month through fake identities earlier this year.
University of Melbourne cybersecurity specialist Andrew Cullen told the ABC on Tuesday that he has seen reports of fake North Korean employees for three to four years. “I don’t think anybody in the West has a particularly strong grasp on exactly how long this has been happening”, Cullen said.
The advisory tells developers to run untrusted code only inside a sandbox or virtual machine. It says infected users should move their assets to a new wallet on a separate device.
Read more: Bitget Hit by $351.6M Hot-Wallet Attack Despite Nearly 3-Hour Transfer Window