Three trade outlets published four separate stories this week about North Korea’s overseas labor operations, and each one covered only half the picture. Read together, they describe a single machine with two output streams: one that plants North Korean workers inside real companies under stolen identities, and one that uses fake job offers to plant malware on the computers of people who are not North Korean at all. The coverage never says these are the same apparatus running in both directions at once. It is, and that is the story this week’s reporting adds up to.
Two stories, filed as if unrelated
On September 16, the Multilateral Sanctions Monitoring Team (MSMT), an eleven-nation coalition of Australia, Canada, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea, the United Kingdom and the United States, released a report on North Korea’s overseas labor program. The Record framed it as a law-enforcement story: Argentina opened a money-laundering investigation into a facilitator named Antonia Doroganova, Pakistan’s Federal Investigation Agency built cases against alleged forgers supplying fake IDs, and Laos disclosed that 19 North Korean nationals it had allowed to work inside the country between 2018 and 2025 have all since departed. The throughline in that account is enforcement against the human infrastructure, the launderers, forgers and front-company operators, that lets North Korean IT workers pose as ordinary remote hires.
Two days later, a joint advisory from the FBI, the U.S. Defense Department’s Cyber Crime Center, and law enforcement in Japan, Germany and Australia described something that reads, on its face, like the opposite crime. CyberScoop’s account and The Register’s both centered on WaterPlum, also tracked as Contagious Interview, in which North Korean operators pose as recruiters, not applicants, and trick real software developers into installing malware disguised as coding-test assignments. Over 30,000 devices infected, more than 7,000 cryptocurrency wallets drained, roughly $10.5 million to $11 million stolen depending on which outlet’s figure you use (the advisory itself was not independently reproducible against these two accounts, and the discrepancy is itself worth noting rather than resolving). A second Record story added that Japanese police dismantled a “laptop farm” tied to the scheme and traced several hundred million yen moved to accounts overseas.
Where the accounts diverge
The disagreement between these pieces is not factual, it is one of framing, and it is instructive. The Record’s MSMT story treats North Korea’s fake-job problem as an immigration and financial-crime issue: workers using stolen identities to get hired, wages confiscated by the regime, enablers laundering the proceeds. CyberScoop and The Register treat the same underlying actor’s fake-job problem as a malware distribution issue: recruiters who do not exist, luring victims who are never actually hired. Neither framing is wrong. But none of the four pieces states plainly that these are mirror images of one operation, run by the same state apparatus, using the same lure (a job that does not exist) pointed in opposite directions depending on which side of the interview North Korea needs to be on.
That matters because it changes what “the North Korea fake-job problem” means for a defender. Read only the MSMT coverage, and the response looks like an HR and vendor-vetting problem, verify who you are hiring. Read only the WaterPlum coverage, and the response looks like an endpoint and developer-tooling problem, do not run code sent by a recruiter. A security leader who only saw one of these three outlets this week would reasonably conclude they only had to solve one of those problems. They have to solve both, because the same government is running both, and a workforce trained to distrust unsolicited recruiter contact is also a workforce equipped to catch a fraudulent IT-worker applicant, and vice versa. CyberTech’s own prior reporting on the WaterPlum malware kit and on North Korean job fraud expanding into healthcare and sales roles covered each side separately, in the same pattern this week’s trade press repeated.
There is a point where the two clusters of reporting agree without saying so directly: North Korea’s fake-job operations, on either side of the interview table, have grown harder to catch precisely because they no longer look like crime. The Rust programming language project, warning its own maintainers this month about recruiter-lure attacks it says are “known to be used by the DPRK,” described the operators as “setting up new but legitimate seeming company profiles,” complete with a LinkedIn presence, so that “a five-minute background check comes back clean.” That is a developer-ecosystem account, not one of the four pieces about this week’s government actions, but it describes the same front-company tradecraft that The Record’s own reporting says North Korean IT workers use to get hired under stolen identities in the first place. Different victims, different outlet, same playbook.
The number that ties them together
The MSMT’s own statement puts scale on the labor side of the operation: an estimated 35,600 to 101,280 North Korean laborers deployed overseas, generating $450 million to $800 million in 2025, with nearly all of it confiscated by Pyongyang before it reaches the workers who earned it. Almost all of those workers sit inside China and Russia, the statement says, including in Russian drone factories. “We encourage all UN Member States to raise awareness and hold responsible parties and facilitators accountable for UNSCR violations, including through domestic action,” the MSMT wrote in its joint statement, a document that also notes the UN Security Council’s own Panel of Experts monitoring this activity was disbanded in April 2024 after a Russian veto, leaving the eleven-nation coalition to do the monitoring the UN body used to do.
The WaterPlum advisory’s numbers describe the other half of the same funding model: crypto theft and credential harvesting from people North Korea never intended to hire, run in parallel with the placement fraud that gets North Koreans hired for real. Both funding streams answer to the same government objective. Both were the subject of major government action inside a 48-hour window this week. No outlet connected the two releases to each other.
The MSMT’s supporting detail sharpens the picture further. Wages for North Korean labor in Russia run up to five times what the same work pays in China, the statement says, and the DPRK confiscates 80 to 90 percent of what its workers earn, in some cases leaving them indebted to the state rather than paid by it. Russia has reportedly built a student-visa channel specifically to give cover to North Korean laborers, some of whom the statement says are manufacturing military drones on Russian soil. None of that detail appears in the WaterPlum-focused coverage, and none of the WaterPlum detail, the $10 million-plus in stolen crypto, the 30,000 backdoored machines, appears in the MSMT-focused coverage. A reader following only one thread this week would have no way to know the other exists.
What it means for the security leader
The practical takeaway is not that any one outlet’s reporting was wrong. It is that a threat actor sophisticated enough to run a nation-state labor-placement fraud scheme and a nation-state malware-distribution scheme through the identical lure, a job offer, will not be caught by a defense built for only one of them. Vendor and hiring due diligence (identity verification, video-call consistency checks, reference validation, cross-checking a candidate’s claimed employment history against a source the candidate did not provide) defends against the placement-fraud half. Treating unsolicited recruiter contact and take-home coding assignments as a standard phishing vector, with sandboxed execution and no direct laptop installs for interview material, defends against the WaterPlum half.
The two controls sit in different parts of most organizations, one in HR and talent acquisition, the other in the security operations center, and this week’s coverage is a useful prompt to check whether either team knows the other exists. Security teams that own only the technical control and leave hiring verification to HR, or the reverse, are covering half of a threat model that this week’s own government actions show is being run as one program by one government, against one lure, worked from both directions at once.
Source: U.S. Department of State

