www.darkreading.com 25 Sept 2026, 14:46 UTC

North Korean IT Workers Used Fake Jobs to Access Global Firms

North Korean IT Workers Used Fake Jobs to Access Global Firms
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇰🇵 WageMole

NORTH Korean operatives are using fake IT-worker applications to gain legitimate employment, access company systems and generate income for the regime. In one case in June 2025, human-risk management firm Nisos suspected an applicant for a remote AI engineering role was part of the operation. After notifying law enforcement, it “hired” the applicant and sent a monitored laptop to a Florida address.

Nisos said the device was operated from a laptop farm and that the individual communicated with 22 other operators and four US-based facilitators while connecting from near the North Korean-Chinese border.

An updated advisory from US, Japanese, Australian and German authorities said the campaign, known as WaterPlum or Contagious Interview, had infected at least 30,000 devices in more than 100 countries and taken funds or credentials from more than 7,000 cryptocurrency wallets. Nisos said operators applied for 170,000 positions during a 10-month investigation and secured 76 roles. The article says AI is helping attackers create convincing applications and apply at scale, while contractors can pose the same access risk as employees.

Organisations are advised to strengthen recruitment processes rather than rely on a single check. Warning signs include VoIP numbers, VPN use, recently created email or LinkedIn accounts, inconsistent or duplicated CV details, limited digital footprints and changes to a candidate’s address when equipment is shipped. None is conclusive alone, but several together should trigger escalation. KnowBe4 has automated checks including phone-carrier identification, email lookups, LinkedIn scans and searches for duplicated contact details.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline