Edited by humans. Written by AI. How our editing works
All articles

Fake Recruiters Turn Coding Tests Into Malware Traps

WaterPlum used fake coding tests to infect 30,000 devices. Learn how jobseekers and employers can reduce malware risk without derailing legitimate hiring.

Rachel "Rach" Kovacs

Written by AI. Rachel "Rach" Kovacs

September 21, 20266 min read
Share:
Fake Recruiters Turn Coding Tests Into Malware Traps

Agencies in Australia, Germany, Japan and the United States say a North Korean-linked group called WaterPlum infected more than 30,000 devices through fake recruitment campaigns.

The joint government warning puts the infections across more than 100 countries. More than 7,000 cryptocurrency wallets were compromised, with attributed losses of at least $10.71 million.

Those numbers describe a large campaign, but they do not provide a denominator for judging how common the attack is among all technology job applications. They also come from one joint advisory. Several outlets have reported the same totals, but that repetition should not be confused with independent confirmation.

The useful lesson sits inside the attack method. WaterPlum operators allegedly posed as recruiters and directed software developers, web designers, engineers and cryptocurrency specialists to download coding assignments or tools for a virtual interview. The files installed remote access trojans and information stealers capable of collecting passwords, files, screenshots, keystrokes, wallet data and identity documents.

A coding test gives malicious software something an ordinary phishing attachment often lacks: a plausible reason to be opened and executed. Developers routinely download repositories, install packages and run unfamiliar code during evaluations. The attacker is borrowing trust from the hiring process, then asking the candidate to perform the dangerous action as proof of competence.

One Laptop, Two Opportunities for the Attacker

The immediate payoff can be theft from a browser, password store or cryptocurrency wallet. Persistent access creates a second opportunity.

The malware described in the reporting can remain accessible months after the fake interview. If the victim later uses the infected computer for legitimate work, the device may become a route into an employer's systems. The Register's account says operators can use compromised machines to pursue credentials, intellectual property, personal data and trade secrets.

That does not mean every infected home laptop will produce a corporate breach. The route depends on what survives, whether the device remains infected, how the eventual employer handles personal computers and what access the new worker receives. A company that issues a freshly configured device and keeps personal machines away from internal systems breaks much of that chain. A bring-your-own-device program with weak enrollment checks leaves more room for it.

This makes pre-employment security part of corporate risk management. Employers cannot reasonably police everything candidates do on personal devices, but they do control their interview design. Requiring applicants to execute opaque packages locally transfers risk to people who have little ability to authenticate the recruiter or inspect the code.

Companies can instead provide browser-based environments, disposable cloud workspaces or clearly documented repositories linked from an authenticated corporate domain. They should also give candidates a published way to verify recruiters and assignments. Security guidance that amounts to “jobseekers should be more careful” leaves the party designing the risky workflow conveniently offstage.

The Campaign Grew from an Older Employment Strategy

The recruiter operation reportedly ran from December 2025 through July 2026, while the group has allegedly conducted financially motivated attacks and cyberespionage since 2023. That timeline sits beside a longer-running North Korean effort to place workers inside foreign technology companies under concealed identities and locations.

Researchers cited in the reporting estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some use accomplices operating laptop farms, where computers physically located in the employer's country help a remote worker appear local. Estimates that the broader worker scheme produces upward of $500 million annually should be treated as estimates, rather than audited revenue figures.

In another example, Amazon's Chief Security Officer Stephen Schmidt, said the company had stopped more than 1,800 suspected North Korean operatives from joining Amazon since April 2024.

The history changes how the fake-recruiter campaign should be understood. Employment fraud can generate salaries, stolen cryptocurrency, identities and access. An identity document taken from a jobseeker may help another operator impersonate that person. Credentials stolen from an infected machine may open access to a later employer or client. The separate activities can therefore reinforce one another even when different operators, victims or malware are involved.

The Mirror-Image Scam Has Important Limits

The comparison is unusually tidy on the surface. In one operation, fraudulent candidates try to enter real companies. In the other, fraudulent recruiters draw real candidates into fake interviews. Both exploit hiring's reliance on documents, remote communication and unfamiliar people performing trust-building exercises.

The mechanics and defenses differ. Detecting a concealed worker involves identity verification, payment scrutiny, interview consistency and monitoring after hiring. Stopping a malicious coding test centers on file execution, recruiter authentication and isolation. Treating every remote applicant as a potential spy would punish legitimate workers without solving the recruiter side of the problem.

The consequences can also diverge. Reporting based on the advisory describes one fraudulent IT worker who extorted a company and published proprietary source code, and another who defaced a website and made it inaccessible. A fake-recruiter infection may instead remain on a personal computer, steal wallet data or wait for later access. The shared asset is trust in the labor market; the path from trust to harm is different.

Employers investigating a suspected fraudulent worker were advised to conduct a full forensic investigation and assume credentials and sensitive data may have been compromised. That response is proportionate after a suspected intrusion, but warning signs such as poor video, a disabled camera or a request for remote work are weak evidence by themselves. Network trouble and camera reluctance occur in perfectly ordinary interviews. Organizations need corroborating indicators and consistent procedures, not nationality-based guesswork.

Safer Interviews Without Turning Recruitment into Airport Security

Jobseekers can reduce exposure with a short verification routine:

  1. Find the opening through the company's own website rather than trusting the link in a message.
  2. Confirm an unfamiliar recruiter through a separate corporate contact channel.
  3. Treat requests to install packages, videoconferencing fixes or coding tools as executable software, because that is what they are.
  4. Use an isolated virtual machine for an assignment when possible, especially if the task requires downloading and running code.
  5. Keep cryptocurrency wallets, saved passwords and identity documents away from the environment used for interview exercises.

An isolated virtual machine adds protection, but the stronger control comes earlier: verify the employer before running its supposed test. Candidates who already executed a suspicious assignment should stop using the affected machine for work or financial activity and seek a malware assessment. Changing passwords from the potentially infected computer can simply hand the replacement credentials to an information stealer.

Hiring teams have their own checklist. Publish recruiter domains, make assignments reproducible, minimize local installation and provide a safe environment for execution. If candidates must use their own machines, tell them what the code does and how its integrity can be checked. A legitimate skills test should evaluate the candidate, not require blind trust in a zip file from a stranger.

WaterPlum's reported scale does not make every coding exercise hostile. It does make “please download this and run it” a security decision, even when the person asking has a polished profile and an attractive job description.

More Like This