Freelance tech pros beware: North Korean cyber criminals are targeting gig workers in a new malware campaign
Fake tests during the recruitment process infect applicants' devices to steal cryptocurrency
Security agencies have issued an alert after North Korean-backed cyber criminals were found posing as recruiters to target freelance IT workers.
WaterPlum - also known as Contagious Interview - targets software developers and IT professionals in Japan, the US, Europe, and other countries.
According to security agencies in Japan, the US, Australia, and Germany, the group has infected at least 30,000 devices in more than 100 countries, and has stolen funds or account credentials from over 7,000 cryptocurrency wallets.
The group's takings amount to $10.7 million so far, with agencies warning workers to remain vigilant for potential scams.
Victims are recruited internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces.
As part of the recruitment process, they're required to take part in technical online virtual interviews or complete assignments - during which they're instructed to carry out a coding assignment or troubleshoot an error in the online video conferencing platform.
However, doing this downloads and executes malicious files hosted on multiple online collaboration platforms and code repositories. These include Node Package Manager (NPM1) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware and related variants.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Once in, the attackers use Remote-Access Trojans (RATs) to maintain connectivity, persistence, and pathways to pivot across victim systems, using infostealers to exfiltrate the victim’s sensitive data and cryptocurrency to a Command-and-Control (C2) IP address for remote management of infected devices or networks.
"Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments," Japanese authorities said. "Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency."
Data targeted for exfiltration includes authentication data stored in web browsers such as IDs and passwords, clipboard information, key-logs, screenshots, and cryptocurrency-wallet data including private keys and seed phrases.
Another North Korean threat campaign
According to the agencies, the criminals behind this are mainly based in North Korea, China, or Russia, with a few in Africa and Southeast Asia.
They're also operating laptop farms to provide fake IT workers, in one case extorting a company over payment and publishing its proprietary source code online. In another, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.
Nick Tausek, lead security automation architect at Swimlane, said the campaign represents an expansion of the familiar North Korean playbook to take job fraud in two directions.
"Fake IT workers seek salary income and trusted access from inside a company. WaterPlum targets legitimate applicants from the outside. Stolen credentials, source code, and identity documents can then support espionage, extortion, or new fraudulent personas," he said.
"The shared laptop farms and IP addresses cited in the advisory suggest these aren’t isolated schemes. Each operation can feed the other. They can steal identities and credentials that help fraudulent workers appear legitimate. Those workers can then gain trusted access to corporate systems, opening further opportunities for theft or disruption."
Ross Filipek, CISO at Corsica Technologies, urged developers, freelancers, and organizations at large to remain on guard.
"One compromised workstation can expose several employers or clients without any of them being directly attacked. Organizations need to know how outside developers access their environments and what information can leave through those accounts. Unknown code should be isolated before execution," said Ross Filipek, CISO at Corsica Technologies.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Orca Security launches new global partner programNews The Partner POD Program and Partner Success Platform aim to help partners improve efficiency, build expertise, and grow their cloud security businesses
-
Cohere CEO Aidan Gomez shares new details on Aleph Alpha mergerNews The companies say the deal, expected to complete this year, will create the first transatlantic sovereign AI firm
-
Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hackerNews New analysis from Huntress reveals the red flags to look out for when taking on new hires
-
‘The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that companies can’t keep upNews The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications
-
Two US nationals sentenced for role in prolific fake worker laptop farmsNews The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees
-
North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victimsNews A fake interview process uses coding tests and repo downloads to deliver malware
-
Cloudflare warns state-backed hackers are ‘weaponizing legitimate enterprise ecosystems’ as ‘living off the land’ attacks surgeNews Chinese, North Korean, and Russian-backed threat groups now favor longer-term compromises over brute force attacks
-
Fake North Korean IT workers are rampant on LinkedIn – security experts warn operatives are stealing profiles to apply for jobs and infiltrate firmsNews The scammers' latest efforts mark a significant escalation in tactics, experts have warned
-
Amazon CSO Stephen Schmidt says the company has rejected more than 1,800 fake North Korean job applicants in 18 months – but one managed to slip through the netNews Analysis from Amazon highlights the growing scale of North Korean-backed "fake IT worker" campaigns