The Grey Terminal
WHERE CODE MEETS CAPITAL
Loading prices…
Powered by CoinGecko
Business & Venture

North Korea Used Fake Recruiters and Job Applicants in Crypto Hiring Scheme

A suspected North Korean IT worker applied to bitFlyer with a forged résumé. Investigators later tied the application to WaterPlum, which posed as a recruiter to target developers.

North Korea Used Fake Recruiters and Job Applicants in Crypto Hiring Scheme

In May 2025, a suspected North Korean IT worker applied directly through Japanese cryptocurrency exchange bitFlyer, Inc.’s recruitment form for an engineering position, using a forged résumé and another person’s identity. Investigators later found that the application shared IP addresses with infrastructure used by WaterPlum, the group publicly attributed to fake job offers targeting developers.

Key Takeaways
  • Japanese cryptocurrency exchange bitFlyer blocks a fraudulent engineering applicant linked to North Korean cyber espionage group WaterPlum.
  • The WaterPlum campaign compromised 30,000 devices across 100 countries and funneled $10.71 million in cryptocurrency to North Korea.
  • International agencies dismantle domestic laptop farms established to disguise foreign state-sponsored operative locations during remote hiring interviews.
Listen to this article
READY

The Japan National Police Agency (NPA) and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, a unit subordinate to the Central Committee of the Workers’ Party of Korea. The advisory also says some WaterPlum actors operate as North Korean IT workers.

The assessment appears in a joint advisory issued September 18, 2026, by Japan’s NPA and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center (DC3), ASD’s Australian Cyber Security Centre, and Germany’s BND and BfV.

The Job Applicant

The bitFlyer applicant’s résumé described a European university education and work experience across Europe and Asia, alongside programming, blockchain, cryptocurrency, and cloud skills. During the video interview, he said he was born in Malaysia and lived in Finland.

Officials said his English did not match the claimed academic and professional background and that he could not explain most of the skills listed on his résumé. The applicant reached the recruitment process through VPN and proxy services.

Advertisement · Press Release

Have a development worth tracking?

Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.

→ Submit a Press Release

Japanese reporting on the investigation said he wanted remote work and cryptocurrency payment and was unwilling to relocate. The reporting also described repeated glances at another monitor and voices in the background. The English-language advisory separately lists those behaviors among observations from interviews with suspected North Korean IT workers.

bitFlyer did not hire the applicant and suffered no damage from the attempt.

The IP Trail

The joint advisory says WaterPlum actors and some North Korean IT workers used the same IP addresses when accessing laptop farms, using crowdsourcing services, and applying for positions at a Japanese cryptocurrency exchange.

WaterPlum, also known as Contagious Interview, approached developers by posing as recruiters for artificial-intelligence, cryptocurrency, and non-fungible-token companies, as well as recruiting services. Targets were given coding tests or other tasks that could deliver malware to their computers.

Japan’s Laptop Farm

The investigation also uncovered what Japanese authorities described as the first laptop farm they had identified, investigated, and dismantled in Japan.

A local enabler placed computers at a residence in Japan. North Korean IT workers operating from abroad remotely controlled the machines so employers and online platforms could see Japanese network connections.

Japanese authorities said several hundred million yen in cryptocurrency was sent to locations outside Japan through the IT-worker activity. That money is separate from the cryptocurrency attributed to WaterPlum’s hacking campaign.

The Wider Campaign

WaterPlum’s wider campaign ran from around December 2025 through July 2026, when authorities said it exploited at least 30,000 devices in more than 100 countries.

The group also exfiltrated funds or account credentials from more than 7,000 cryptocurrency wallets. Authorities said ¥1.7 billion, equivalent to about $10.71 million, in cryptocurrency assets was transferred to North Korea.

That figure does not mean 7,000 wallets were emptied. The official account refers to funds or account credentials taken from more than 7,000 wallets and the subsequent transfer of cryptocurrency assets.

For companies hiring remote technical workers, the investigation turns the hiring desk into part of the security perimeter. The person offering the job may be part of the intrusion, while the person applying for it may be trying to get inside the company.

TERMINAL LAYER

Activate Terminal Layer

Structural analysis of the systems, pressures, and stakeholders behind this story.

FAQ

Frequently Asked Questions

01

What is the WaterPlum cyber campaign identified by international authorities?

WaterPlum is a state-sponsored North Korean cyber threat cluster subordinate to the Munitions Industry Department. The group deploys deceptive recruitment operations, known as Contagious Interview, to infect developer devices through malicious coding assessments. A joint advisory from the Federal Bureau of Investigation and Japan's National Police Agency linked operatives to direct enterprise infiltration attempts.
02

Why does remote IT worker infiltration matter for cryptocurrency exchanges?

Rogue nation states use fraudulent technical hires to establish internal administrative access to private blockchain infrastructure and hot wallets. Japanese exchange bitFlyer neutralized the insider threat before unauthorized access compromised customer funds or internal corporate repositories. The tactic transforms corporate recruitment workflows into primary physical and digital security boundaries for global digital asset platforms.
03

How did the operative attempt to infiltrate bitFlyer?

The applicant submitted a falsified curriculum vitae claiming European academic credentials and international blockchain development experience. During video evaluations, hiring managers observed suspicious off-screen coaching, contradictory language proficiency, and background acoustic anomalies. Telemetry analysis later matched the candidate's proxy internet protocol addresses directly to malicious command infrastructure used by WaterPlum.
04

How do laptop farms facilitate North Korean IT worker schemes?

Domestic collaborators host physical laptops inside residential properties to provide authentic regional internet protocol connections for overseas operatives. Japanese law enforcement successfully dismantled their first domestic laptop farm after discovering hundreds of millions of yen routed abroad. The distributed hardware setups allow sanctioned foreign workers to bypass commercial employment identity verification and corporate geofencing firewalls.
05

How are tech companies screening remote applicants to detect state-sponsored actors?

Security protocols now mandate rigorous identity verification checks alongside physical device biometric authentication during technical interviews. Human resources teams correlate candidate video latency, monitor audio discrepancies, and cross-reference network IP ranges with threat intelligence advisories. Organizations like the Cybersecurity and Infrastructure Security Agency urge firms to refuse cryptocurrency payroll requests from unverified contractors.

You Might Also Like

THE GREY TERMINAL
🛡
Alex Reeve

Alex Reeve is a contributing writer for The Grey Terminal Her articles provide timely insights and analysis across these interconnected industries, including regulatory updates, market trends, token economics, institutional developments, platform innovations, stablecoins, meme coins, policy shifts, and the latest advancements in AI, applications, tools, models, and their broader implications for technology and markets.

The views and opinions expressed by the author in this article are her own and do not necessarily reflect the official position of The Grey Terminal, its management, editors, or affiliates. This content is provided for informational and educational purposes only and does not constitute financial, investment, legal, or tax advice. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets, cryptocurrencies, or financial matters. The Grey Terminal and its contributors are not responsible for any losses incurred from reliance on this information.