Coding tests handed out in fake job interviews have infected more than 30,000 devices, according to a joint advisory published Thursday by law enforcement and security agencies in Australia, Germany, Japan and the United States. They attribute the campaign, called WaterPlum, to North Korea.

The attackers pose as recruiters and approach web designers, engineers, and cryptocurrency and Web3 specialists. During the interview they send the candidate a file described as a programming assignment or test.

Opening it installs a remote access trojan and an information stealer.

What gets taken

The malware collects credentials, clipboard contents, keystrokes and cryptocurrency wallet data. According to the advisory, it also grabs identity documents, intellectual property and trade secrets.

More than 7,000 cryptocurrency wallets have been compromised. Thefts attributed to the campaign total $10.71 million.

Stolen identities

The stolen identity documents feed a second scheme. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory says.

The Register notes that the broader IT worker fraud is estimated to bring North Korea $500 million a year, from an estimated 100,000 such workers worldwide.