NewsCryptoNorth Korean Fake Recruiters Infect 30,000 Devices, Steal $10.7 Million in Crypto

North Korean Fake Recruiters Infect 30,000 Devices, Steal $10.7 Million in Crypto

Author: Cointelegraph·

Key Takeaways

  • WaterPlum, also known as 'Contagious Interview,' stole at least $10.7 million by posing as recruiters for cryptocurrency, AI and NFT companies, according to a joint advisory from Japan, Germany, Australia and the United States.
  • The group lured job seekers on social media, online job, gig and freelance platforms into running malicious files disguised as coding assignments or fixes for video-conferencing errors.
  • At least 30,000 devices in more than 100 countries were infected, with funds or credentials extracted from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
  • Japanese and US authorities assess that WaterPlum actors and some North Korean IT workers operate under North Korea's Munitions Industry Department.
  • Unlike the $1.5 billion Bybit theft attributed to North Korea, the WaterPlum campaign accumulated its proceeds from thousands of individual victims rather than a single exchange.
North Korean Fake Recruiters Infect 30,000 Devices, Steal $10.7 Million in Crypto

North Korean hacking group WaterPlum has stolen at least $10.7 million by posing as recruiters for legitimate cryptocurrency and artificial intelligence companies, targeting unsuspecting job seekers with malware, according to a joint cybersecurity advisory issued by authorities in Japan, Germany, Australia and the United States. Joint advisories of this kind are published when several national authorities coordinate to warn the public about a shared threat.

Also tracked as “Contagious Interview,” the group targets software developers and IT professionals worldwide. Authorities said the fake recruiters also impersonated non-fungible token (NFT) companies and used recruiting services.

“The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” the advisory stated.

How the operation worked

According to the advisory, WaterPlum lured job seekers through social media platforms, online job platforms, gig work platforms and freelance marketplaces. During the recruitment process, victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors. In effect, routine steps in a remote hiring workflow — completing a technical test or fixing a video call — doubled as the malware delivery channel.

Once the cyber actors obtained backdoor access to a victim’s computer, they used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. Successful infections also create opportunities for WaterPlum actors to infiltrate the organizations that employ the unwitting developers.

WaterPlum infected at least 30,000 devices in more than 100 countries, with funds or account credentials extracted from over 7,000 cryptocurrency wallets between December 2025 and July 2026 — a spread that makes the campaign global in scale rather than confined to a single region.

The advisory noted that the damage can extend beyond stolen cryptocurrency. Stolen identity documents allow North Korean IT workers to impersonate victims and earn income, and sensitive information could be used for.

Ties to North Korea’s IT worker program

The advisory links WaterPlum to North Korea’s broader campaign of placing IT workers inside foreign companies, as Cointelegraph previously reported. Japanese and US authorities assess that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department.

In one case described in the advisory, a suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange using a forged resume. The exchange rejected the applicant after finding discrepancies during the interview, including an inability to explain in detail the skills listed on the resume.

A more recent case surfaced in July, when Cointelegraph reported that Consensys had unknowingly engaged a North Korea-linked developer as a consultant. The company told Cointelegraph it terminated the individual’s access after discovering the threat, and an investigation found no theft of assets or data, no malicious code deployment and no impact on user safety. Taken together, the cases show that detection can surface at different stages — during the interview process or after a contract has already begun.

A persistent funding stream

The reported campaign is the latest example of North Korea’s persistent use of cryptocurrency theft to raise funds despite years of warnings and enforcement actions. The FBI attributed the $1.5 billion Bybit theft in February 2025 to North Korea, while US authorities have warned about the country’s undercover IT workers since at least 2018. Unlike the Bybit breach, which targeted a single exchange, the WaterPlum campaign accumulated its proceeds from thousands of individual victims.

Cointelegraph Magazine has separately reported on North Korea driving an onchain malware surge and the CoinEx shutdown in its Asia Express column.

Source: Cointelegraph