NORTH Korean operatives are using fake IT-worker applications to gain legitimate employment, access company systems and generate income for the regime. In one case in June 2025, human-risk management firm Nisos suspected an applicant for a remote AI engineering role was part of the operation. After notifying law enforcement, it “hired” the applicant and sent a monitored laptop to a Florida address.
Nisos said the device was operated from a laptop farm and that the individual communicated with 22 other operators and four US-based facilitators while connecting from near the North Korean-Chinese border.
An updated advisory from US, Japanese, Australian and German authorities said the campaign, known as WaterPlum or Contagious Interview, had infected at least 30,000 devices in more than 100 countries and taken funds or credentials from more than 7,000 cryptocurrency wallets. Nisos said operators applied for 170,000 positions during a 10-month investigation and secured 76 roles. The article says AI is helping attackers create convincing applications and apply at scale, while contractors can pose the same access risk as employees.
Organisations are advised to strengthen recruitment processes rather than rely on a single check. Warning signs include VoIP numbers, VPN use, recently created email or LinkedIn accounts, inconsistent or duplicated CV details, limited digital footprints and changes to a candidate’s address when equipment is shipped. None is conclusive alone, but several together should trigger escalation. KnowBe4 has automated checks including phone-carrier identification, email lookups, LinkedIn scans and searches for duplicated contact details.