The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In 2025, North Korean threat actors operating under the WaterPlum campaign (also known as Contagious Interview) have successfully infiltrated over 100 countries through fraudulent IT worker schemes. The operation infected at least 30,000 devices and compromised over 7,000 cryptocurrency wallets by embedding fake remote workers into technology companies worldwide. These operatives used sophisticated social engineering, AI-enhanced resumes, and laptop farms to maintain persistent access while generating regular income for the North Korean regime. The campaign demonstrates unprecedented scale, with attackers applying for 170,000 positions over 10 months and successfully placing 76 fraudulent workers across various organizations.

This incident highlights the growing threat of state-sponsored insider attacks leveraging remote work vulnerabilities and AI-powered deception techniques. As organizations increasingly rely on distributed workforces and face talent shortages in cybersecurity roles, these sophisticated employment fraud schemes represent a critical evolution in nation-state attack vectors that traditional security controls struggle to detect.

Why This Matters Now

The proliferation of AI tools has dramatically reduced the cost and skill required for threat actors to conduct employment fraud at massive scale, while remote work policies have expanded attack surfaces beyond traditional network perimeters, making insider threat detection more critical than ever.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Key indicators include newly created LinkedIn profiles with extensive experience claims, VoIP phone numbers, VPN usage for document submission, and inconsistent digital footprints across platforms.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius of North Korean IT workers by constraining their lateral movement and egress capabilities despite legitimate initial access. Segmentation controls could limit their ability to explore beyond authorized resources and establish unauthorized data exfiltration channels.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Device-level security posture assessment could likely identify malicious tooling installation patterns or anomalous behaviors on corporate laptops during initial deployment phases

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based access controls would likely constrain operatives to only role-specific resources, reducing their ability to install unauthorized tools or access systems beyond their designated job functions

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation policies would likely constrain cross-environment exploration and limit access to only authorized workloads and services required for their specific job responsibilities and department functions

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Traffic analysis across cloud environments could likely detect anomalous communication patterns and unauthorized use of personal communication platforms for coordination activities beyond normal business communications

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely restrict unauthorized data transfers and limit access to sensitive intellectual property repositories based on role-specific data classification and access requirements

Impact (Mitigations)

Organizations would likely experience reduced exposure scope with sensitive assets protected by segmentation controls, though salary-based revenue generation through legitimate employment would continue until identity fraud detection

Impact at a Glance

Affected Business Functions

  • Human Resources and Talent Acquisition
  • Information Technology Operations
  • Intellectual Property and R&D
  • Financial Operations and Payroll
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $75,000

Data Exposure

Potential exposure of proprietary source code, intellectual property, internal communications, employee data, and cryptocurrency wallet credentials. The WaterPlum campaign has reportedly exfiltrated funds from over 7,000 cryptocurrency wallets and infected 30,000+ devices across 100+ countries.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to limit insider access to sensitive resources and prevent lateral movement
  • • Deploy Multicloud Visibility & Control solutions to detect anomalous interactions and suspicious automation patterns across hybrid environments
  • • Establish Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration to external destinations
  • • Enhance Threat Detection & Anomaly Response capabilities to identify covert tools like AnyDesk and baseline normal employee behavior patterns
  • • Strengthen HR processes with automated candidate verification using Cloud Native Security Fabric controls to detect fraudulent applications at scale

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image