North Korean hackers turned online job hunting into a weapon. Between December 2025 and July 2026, security teams discovered that recruiters on platforms like LinkedIn were actually WaterPlum operators running a coordinated campaign against software developers, web designers, and cryptocurrency specialists.
TL;DR
This campaign infected at least 30,000 computers in over 100 countries and resulted in more than $10.7 million stolen in cryptocurrency. Hackers posed as legitimate recruiters to run fake interviews that required candidates to install malicious software packages. The attacks targeted developers who were looking for work or freelance opportunities using tools like npm and pip. Small teams face the same risks — verify recruiter identities with a phone call, treat code installation requests from strangers with suspicion, keep your endpoints clean and up to date, enable MFA on everything that supports it, and maintain fresh backups before anyone calls you.
How the recruitment scam actually works
The attackers send messages through job boards and professional networks targeting people skilled in cryptography, blockchain development, web technologies, or any technology stack involving code packages. They craft profiles that appear entirely legitimate with real-seeming experience and company names.
Once the candidate responds and moves toward an interview — sometimes using video tools like Zoom or Teams — the WaterPlum operators steer the conversation toward a practical exercise. They claim some code runs through popular package managers like npm for Node.js projects or pip for Python scripts. The task is always urgent, framed as mandatory to pass screening or prove technical competence.
Running that software installs a malicious payload called Contagious Interview malware that gives the attacker full control over the running computer and begins exfiltrating wallet credentials and cryptocurrency from any connected devices.
Why this campaign matters for small teams in Washington County
The WaterPlum attack required no sophisticated exploit against your web server. A phishing message lands, someone responds to a recruiter message, opens a link or installs requested software. That same path applies whether you run five developers or five hundred.
Small businesses and nonprofits often have staff who wear multiple hats. A developer also handles customer support tickets and finances on the same machine. Malware planted during a fake interview task runs silently until it has already stolen sensitive data. Schools with computer clubs face the same danger when volunteer organizers are searching for paid internships or student workers.
Security teams have confirmed that this attack vector remains active as we publish this post. The pattern shifts slightly — attackers now add language about open-source tools and supply-chain compromise to make the request seem more justified — but the mechanism is unchanged: convince someone to run unfamiliar code.
Practical steps to stay safe
The checklist is shorter than the headlines imply, and every item applies to teams of any size. Start with communication discipline:
- Verify recruiter identity. Ask for a direct phone number or email address on file at their company and make an independent call or send an email using only publicly available contact information. Legitimate companies can confirm whether a particular job posting exists or if the candidate should be considered.
- Treat software download requests with suspicion outside your organization domain. If a recruiter asks you to install something from GitHub, npmjs, PyPI, or any external URL outside of standard operating procedures and your company guidelines, ask for written authorization from the hiring manager. Your IT department should review any external installation that runs on production machines regardless of job context.
- Keep endpoints updated and hardened against remote code execution. Malware thrives when it can run arbitrary commands without restriction. Security updates fix known vulnerabilities that attackers use to plant initial access or maintain access if the first step fails.
- Enable multi-factor authentication everywhere possible. The WaterPlum operators needed wallet passwords and account credentials to move money once they had code execution. Modern MFA implementations protect even compromised accounts from misuse by attackers because possession of a password alone is no longer sufficient to move or drain crypto assets.
- Back up important data regularly and test restoration procedures quarterly. While the WaterPlum campaign focused on cryptocurrency theft rather than ransomware, any malware can pivot to file overwriting, configuration tampering, or other destructive behavior depending on what code packages it installs. Regular backups ensure you can recover from compromise without paying ransoms or restoring from outdated versions containing malicious files.
The WaterPlum campaign shows how attackers repurpose ordinary work processes to achieve financial harm. Job boards and professional networking sites remain the place where businesses find talented people, but the same venues host attackers who understand that people looking for income opportunities can become targets without realizing it.
The takeaway
Your team doesn't need to stop hiring — they just need verification steps integrated into the normal process. Before accepting any code from an external source, confirm the recruiter's identity through a phone number listed on your job posting page. Ask IT to review unfamiliar installation requests before approving them for production systems. Keep your security updates current and MFA enabled wherever available.
If you would like help reviewing your team's hiring workflow for these kinds of risks, that is exactly the kind of thing we look at. It starts with our free 30-minute IT review, and we work with small teams and ministries around Washington County.