North Korea's WaterPlum Group Used Fake Job Interviews to Steal $10.7 Million in Crypto
Key Takeaways
- •The WaterPlum campaign, also known as Contagious Interview, compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026.
- •Attackers posed as recruiters for cryptocurrency, artificial intelligence, or NFT companies on social media, employment websites, freelance platforms, and recruiting services, then instructed candidates to download malicious files or developer packages during technical interviews.
- •The operation moved approximately $10.71 million in cryptocurrency linked to more than 7,000 wallets.
- •Malware strains including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle established remote access and harvested browser credentials, keystrokes, screenshots, clipboard data, identity documents, and cryptocurrency wallet details.
- •The operation overlaps with North Korea's broader IT worker schemes, which rely on stolen identities, intermediaries, remote access, and laptop farms to place North Korean workers in overseas technology jobs.

North Korean cyber actors compromised thousands of devices and stole cryptocurrency in a global campaign that used fake job interviews to target technology professionals, according to a report by CryptoMeter io.
The group behind the operation, known as WaterPlum or Contagious Interview, focused on software developers, web designers, blockchain specialists, and other IT professionals. Authorities said the campaign compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026. The operation moved approximately $10.71 million in cryptocurrency linked to more than 7000 wallets, underscoring how North Korea continues to pair social engineering with technical attacks to generate illicit revenue from the crypto industry.
How the fake interviews worked
WaterPlum operators approached job seekers through social media, employment websites, freelance platforms, and recruiting services, often posing as recruiters for cryptocurrency, artificial intelligence, or NFT companies.
After establishing contact, the attackers invited candidates to technical interviews or coding tests, then instructed them to download files or developer packages to complete an assignment or fix a supposed technical problem.
The downloads carried multiple malware strains, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle variants. Once installed, the malware established remote access and harvested sensitive information, including browser credentials, keystrokes, screenshots, clipboard data, identity documents, and cryptocurrency wallet details. The range of named strains and variants points to a multi-tool operation, and it gives security teams specific malware families to reference when reviewing potentially exposed devices.
Why crypto professionals were targeted
The campaign concentrated heavily on individuals with access to digital assets and blockchain infrastructure. A compromised personal computer could expose wallet credentials directly, while stolen credentials allowed attackers to pursue additional targets. If a victim later joined a technology company, the infected device could also serve as a potential pathway into corporate systems. The pattern also shows why the initial compromise sits with the individual: victims installed the malicious files themselves as part of an ordinary-seeming hiring step, placing the malware on their own devices rather than requiring a direct attack on an employer's systems.
The operation overlaps with North Korea's broader IT worker schemes, which rely on stolen identities, intermediaries, remote access, and “laptop farms” to place North Korean workers in overseas technology jobs. Both schemes turn the hiring process into an entry point — one delivers malware to job candidates, the other places North Korean workers inside overseas companies.
A growing risk for crypto firms
WaterPlum highlights a persistent weakness in crypto security: the hiring process itself can become an attack surface. Job candidates are advised to avoid running untrusted code during interviews, and companies can verify applicants' identities, employment histories, technical claims, contact details, and network locations before granting access to sensitive systems. With activity documented through July 2026 across more than 100 countries, candidates and employers auditing recent hiring interactions have a concrete pattern to check for: any interview step that required downloading files or developer packages outside verified channels.
For crypto businesses, the incident reinforces the need to treat recruitment as part of cybersecurity. A convincing interview invitation can be more than a career opportunity — it may be the first step in a targeted attempt to reach valuable digital assets.