Executive Summary
In 2025, North Korean threat actors operating under the WaterPlum campaign (also known as Contagious Interview) have successfully infiltrated over 100 countries through fraudulent IT worker schemes. The operation infected at least 30,000 devices and compromised over 7,000 cryptocurrency wallets by embedding fake remote workers into technology companies worldwide. These operatives used sophisticated social engineering, AI-enhanced resumes, and laptop farms to maintain persistent access while generating regular income for the North Korean regime. The campaign demonstrates unprecedented scale, with attackers applying for 170,000 positions over 10 months and successfully placing 76 fraudulent workers across various organizations.
This incident highlights the growing threat of state-sponsored insider attacks leveraging remote work vulnerabilities and AI-powered deception techniques. As organizations increasingly rely on distributed workforces and face talent shortages in cybersecurity roles, these sophisticated employment fraud schemes represent a critical evolution in nation-state attack vectors that traditional security controls struggle to detect.
Why This Matters Now
The proliferation of AI tools has dramatically reduced the cost and skill required for threat actors to conduct employment fraud at massive scale, while remote work policies have expanded attack surfaces beyond traditional network perimeters, making insider threat detection more critical than ever.
Attack Path Analysis
North Korean IT workers infiltrated organizations through fraudulent remote hiring processes, gaining legitimate access to corporate systems and infrastructure. Once embedded, they maintained persistent access while avoiding detection to generate steady revenue for the DPRK regime through salary collection and potential intellectual property theft.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
DPRK operatives submitted fraudulent job applications using AI-generated resumes and fake identities, successfully passing HR screening processes to gain legitimate remote employment and receive corporate devices
MITRE ATT&CK® Techniques
Phishing: Spearphishing via Service
Valid Accounts: Cloud Accounts
Compromise Accounts: Email Accounts
Establish Accounts: Social Media Accounts
Proxy: Multi-hop Proxy
Data from Information Repositories
Exfiltration Over C2 Channel
Trusted Relationship
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity Verification and Authentication
Control ID: ID.AM-1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Digital Operational Resilience Act (DORA) – ICT Third-party Risk Management
Control ID: Article 8
PCI DSS 4.0 – User Identity Verification
Control ID: 8.2.1
ISO 27001:2022 – Screening
Control ID: A.7.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Primary target for North Korean IT worker infiltration campaigns seeking remote positions, requiring enhanced HR screening processes and insider threat detection capabilities.
Computer Software/Engineering
High-risk sector targeted by DPRK operatives applying for AI and software engineering roles, necessitating robust identity verification and background checking procedures.
Human Resources/HR
Critical frontline defense requiring process revamps, automated screening tools, and training to detect fraudulent applications and suspicious candidate digital footprints effectively.
Financial Services
Vulnerable to cryptocurrency wallet theft and account credential exfiltration through embedded operatives, demanding strengthened contractor vetting and access controls.
Sources
- Stopping IT Worker Scams Requires Revamped HR Processhttps://www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-processVerified
- CISA Advisory on North Korean IT Workershttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-121aVerified
- FBI Advisory on DPRK IT Worker Schemeshttps://www.fbi.gov/news/press-releases/fbi-releases-indicators-of-compromise-associated-with-dprk-it-workersVerified
- KnowBe4 Security Incident Reporthttps://blog.knowbe4.com/knowbe4-announces-hiring-of-fake-north-korean-it-workerVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of North Korean IT workers by constraining their lateral movement and egress capabilities despite legitimate initial access. Segmentation controls could limit their ability to explore beyond authorized resources and establish unauthorized data exfiltration channels.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Device-level security posture assessment could likely identify malicious tooling installation patterns or anomalous behaviors on corporate laptops during initial deployment phases
Control: Zero Trust Segmentation
Mitigation: Identity-based access controls would likely constrain operatives to only role-specific resources, reducing their ability to install unauthorized tools or access systems beyond their designated job functions
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely constrain cross-environment exploration and limit access to only authorized workloads and services required for their specific job responsibilities and department functions
Control: Multicloud Visibility & Control
Mitigation: Traffic analysis across cloud environments could likely detect anomalous communication patterns and unauthorized use of personal communication platforms for coordination activities beyond normal business communications
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely restrict unauthorized data transfers and limit access to sensitive intellectual property repositories based on role-specific data classification and access requirements
Organizations would likely experience reduced exposure scope with sensitive assets protected by segmentation controls, though salary-based revenue generation through legitimate employment would continue until identity fraud detection
Impact at a Glance
Affected Business Functions
- Human Resources and Talent Acquisition
- Information Technology Operations
- Intellectual Property and R&D
- Financial Operations and Payroll
Estimated downtime: N/A
Estimated loss: $75,000
Potential exposure of proprietary source code, intellectual property, internal communications, employee data, and cryptocurrency wallet credentials. The WaterPlum campaign has reportedly exfiltrated funds from over 7,000 cryptocurrency wallets and infected 30,000+ devices across 100+ countries.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit insider access to sensitive resources and prevent lateral movement
- • Deploy Multicloud Visibility & Control solutions to detect anomalous interactions and suspicious automation patterns across hybrid environments
- • Establish Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration to external destinations
- • Enhance Threat Detection & Anomaly Response capabilities to identify covert tools like AnyDesk and baseline normal employee behavior patterns
- • Strengthen HR processes with automated candidate verification using Cloud Native Security Fabric controls to detect fraudulent applications at scale



