Honolulu/ Crime & Emergencies

North Korean Hackers Hit 30,000 Devices in Fake Tech Recruiter Scheme

AI Assisted Icon
Published on September 19, 2026
North Korean Hackers Hit 30,000 Devices in Fake Tech Recruiter SchemeSource: Coast Guard / Honolulu Police Department

The FBI's Honolulu field office is sounding the alarm on a North Korean cyber group posing as prospective employers to hack the computers of software developers and IT professionals around the world. The group, known as WaterPlum or by its more common nickname, Contagious Interview, uses fake dream-job offers to compromise job seekers' computer networks, harvest sensitive data, and steal cryptocurrency, according to the bureau's Honolulu office.

In a post from its official account, FBI Honolulu

said WaterPlum impersonates legitimate AI, NFT, and cryptocurrency companies, using recruiting platforms to reach IT professionals in Japan, the United States, Europe, and beyond. The warning lines up with a joint cybersecurity advisory issued the same day by international authorities, which found that WaterPlum has infected more than 30,000 devices across over 100 countries, pulled credentials from 7,000 cryptocurrency wallets, and received about $10.71 million in controlled wallets, while several hundred million yen was sent overseas.

the FBI's Internet Crime Complaint Center

.

Japan's National Police Agency was among the partners in the joint advisory on North Korean WaterPlum, commonly referred to as Contagious Interview, and its targeting of IT professionals. The joint advisory assessed that WaterPlum's hackers and North Korea's overseas IT workers both answer to Bureau 313 — the 313 General Bureau of the Munitions Industry Department under North Korea's Workers' Party Central Committee, per the same IC3 report.

How the Fake Job Offers Actually Work

The scheme's technical mechanics have been building for months. Researchers at Jamf Threat Labs reported in January that Contagious Interview operators adapted their delivery method to exploit Microsoft Visual Studio Code, tricking software developers into cloning and trusting weaponized GitHub or GitLab code repositories that quietly run hidden commands to install backdoors, according to the report cited by Dark Reading.

Cybersecurity firm Socket has tracked 26 malicious npm packages tied to the campaign, which rely on deceptive developer dependencies to deploy infostealers and remote access trojans including BeaverTail and Ferret, per the firm's research.

Laptop Farms and the Push to Cut Off the Money

Alongside the malware threat, North Korea has for years relied on overseas IT workers using stolen or fabricated identities to land legitimate remote jobs, funneling their wages back to the regime. Japan's National Police Agency disclosed in its September advisory that it had dismantled a laptop farm operating inside Japan, where local accomplices hosted physical computers that let overseas North Korean IT workers connect remotely and dodge hiring safeguards.

U.S. authorities have also pursued domestic enablers of North Korean IT-worker schemes.

Under UN Security Council Resolution 2397, all UN member states are required to repatriate North Korean foreign wage earners specifically to prevent that revenue from funding Pyongyang's banned nuclear and ballistic missile programs, according to a joint advisory released in July. Estimates from South Korea's National Intelligence Service, cited by Wikipedia, indicate North Korea's state cyber workforce grew from roughly 6,800 personnel in 2022 to 8,400 in 2024, underscoring how much manpower the regime has poured into cyber theft and remote employment infiltration.

A Pattern Hoodline Has Tracked Before

This isn't the first time North Korea's IT worker schemes have made headlines through Hoodline's reporting. An Arizona woman was sentenced over an $17M fraud scheme for helping North Korean IT workers infiltrate American businesses.

For now, the FBI Honolulu field office is urging job seekers and IT professionals to stay alert to unsolicited recruiting outreach.