Beware DPRK job scams, ASD warns, but won’t confirm local impact

Key points

ASD has joined Japan, Germany and the US in warning that North Korean actor WaterPlum, also known as Contagious Interview, poses as recruiters to target IT professionals with malware.

Beware DPRK job scams, ASD warns, but won't confirm local impact

Beware DPRK job scams, ASD warns, but won't confirm local impact

Key points

  • ASD has joined Japan, Germany and the US in warning that North Korean actor WaterPlum, also known as Contagious Interview, poses as recruiters to target IT professionals with malware.
  • WaterPlum has infected more than 30,000 devices in over 100 countries, draining more than 7000 cryptocurrency wallets and transferring roughly $15.4 million to the DPRK.
  • The MSMT report found North Korea earned US$450 million to US$800 million in 2025 by deploying between 35,600 and 101,280 overseas labourers, including IT workers using stolen identities, across at least 17 countries.




Beware DPRK job scams, ASD warns, but won't confirm local impact










The Australian Signals Directorate (ASD) has joined Japan, Germany and the United States in warning that North Korean cyber actors are now posing as recruiters to target IT professionals worldwide.

This flips an earlier script which has seen IT workers from the communist dictatorship seek employment in Western nations, for a range of nefarious purposes including cryptocurrency theft, spying, information stealing and sabotage.

A joint advisory from intelligence agencies in Japan, Germany and the US describes how a threat actor code-named WaterPlum and alternatively, Contagious Interview, has lured IT professionals with fake job opportunities.

WaterPlum actors have posed as artificial intelligence (AI), cryptocurrency and non-fungible tokens (NFT) companies, sometimes operating through recruiting services.

Once a target engages with WaterPlum’s fake hiring process, the actors seek to compromise their device with malware to harvest sensitive information and to steal cryptocurrency.

WaterPlum is said to have infected more than 30,000 devices in over 100 countries with malware.

This has enabled them to drain more than 7000 cryptocurrency wallets, transferring 1.7 billion Japanese yen, or roughly $15.4 million, to the DPRK.

ASD would not be drawn on whether any Australian individuals or organisations had been affected by WaterPlum when asked by iTnews.

“The tactics, techniques and procedures outlined in this advisory are being used against organisations across the world,” an ASD spokesperson said.

“Australians and Australian businesses are encouraged to review this advisory to manage risks of DPRK cyber actors attempting to infiltrate networks, harvest sensitive information, and steal cryptocurrency.

“Advisories are published when doing so is assessed to be in Australia’s interests, including when they can meaningfully improve the resilience of potential victim organisations,” the spokesperson added.

Revenue-raking DPRK “IT workers” subcontract jobs

North Korean employment scams run in both directions.

Prior to the WaterPlum advisory, the Multilateral Sanctions Monitoring Team (MSMT), a body Australia sits on alongside Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea, the United Kingdom and the United States, published its findings on North Korea’s use of overseas labour to fund the regime and to evade United Nations sanctions.

Whereas WaterPlum actors pose as employers, the MSMT report describes DPRK nationals acting as employees, using stolen or fabricated identities to secure jobs with companies that have no idea who they have actually hired.

The program has earned North Korea an estimated US$450 million to US$800 million in 2025 alone, deploying between 35,600 and 101,280 labourers across at least 17 countries, the MSMT report found.

Most of the North Korean labourers work in textiles and food processing, but IT workers earn the highest revenue per person of any category the report tracks.

The DPRK government confiscates 80 to 90 percent of wages earned by its overseas labourers, in some cases leaving them indebted to their own government, the report found.

Conditions can be harsh, according to one leaked account believed to belong to a Russia-based North Korean IT worker cell.

The account’s Slack activity showed five active chat groups of roughly 10 workers each under a clear chain of command, along with contracted project lists and forged passport data, the MSMT report said.

In one group, a person believed to be the supervisor told workers, “You should work at least 14 hours or more”, and worktime tracking software was installed on their devices to enforce it.

In another, one worker asked “Do you have a passport?”, drawing offers of “A Canadian one” and “A Japanese one” from others in the chat, which the report said points to IT workers helping each other bypass identity checks.

There’s an irony in one of the report’s final findings: having secured jobs with Western companies under false pretences, some North Korean IT workers have begun subcontracting that same work to developers in lower-cost labour markets themselves, apparently to protect their own margins.

As with the ASD advisory, Australia’s name appears in the MSMT report, yet no local data appears inside it.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.