North Korea's Fake Job Interviews Drained $11M From 7,000 Crypto Wallets

A joint advisory from seven agencies says a North Korean-linked crew posing as recruiters stole funds or credentials from over 7,000 cryptocurrency wallets and moved about ¥1.7 billion (roughly $10.71 million) to North Korea. The group, known as WaterPlum or Contagious Interview, infected at least 30,000 devices across more than 100 countries by luring developers into fake technical interviews and delivering malware-packed files.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
North Korea's Fake Job Interviews Drained $11M From 7,000 Crypto Wallets

Why It Matters

The advisory links this social-engineering campaign and North Korea's remote IT worker program to the 313 General Bureau, indicating state involvement in a large-scale, cross-border crypto theft operation. The campaign forms part of a broader pattern: security firms attribute a sizable share of 2025 crypto thefts to North Korea-linked actors, highlighting continued risks to developers and crypto platforms.

Key Facts

  • Advisory date: September 18, 2026
  • Agencies involved: Japan's NPA and National Cybersecurity Office, FBI, U.S. DoD Cyber Crime Center, Australian Cyber Security Centre, Germany's BND and BfV
  • Operation names: WaterPlum (NPA) / Contagious Interview (security industry)
  • Infected devices: At least 30,000 devices
  • Countries affected: More than 100 countries

A multinational advisory published on September 18 says a North Korean-affiliated crew used fake job interviews to compromise developers and exfiltrate cryptocurrency and credentials. Authorities attribute the operation to a group Japan's National Police Agency calls WaterPlum and the security industry dubs Contagious Interview. Investigators report the campaign infected at least 30,000 devices across over 100 countries between about December 2025 and July 2026.

The attackers targeted web designers, engineers and specialists in crypto, blockchain and Web3, approaching candidates via social media, job boards and freelance marketplaces. Victims were given technical interviews or coding tasks and instructed to download files from developer platforms; those files contained malware families the advisory names, including BeaverTail, InvisibleFerret and StoatWaffle, the latter concealed within blockchain-themed repositories.

The seven signing agencies — Japan's National Police Agency and National Cybersecurity Office, the U.S. FBI and Department of Defense Cyber Crime Center, Australia's Australian Signals Directorate's Cyber Security Centre, and Germany's BND and BfV — say the crew took funds or credentials from more than 7,000 crypto wallets and moved about ¥1.7 billion (around $10.71 million) to North Korea. The agencies assess that WaterPlum and parts of North Korea's remote IT worker program report to the 313 General Bureau of the Munitions Industry Department under the Workers' Party central committee, and they cite shared IP addresses and other operational overlaps as evidence the activities are linked.

Japanese investigators also dismantled what they described as a domestic laptop farm used to operate the scheme, marking the first such takedown in Japan; authorities found indications that several hundred million yen in cryptocurrency had been transferred abroad. The advisory notes behavioral indicators of the operation, such as use of AI face-swapping in interviews, reliance on free machine-translation and AI tiers, and cultural patterns consistent with North Korean work schedules and holidays. Security firms have previously tied a large share of 2025 crypto losses to North Korea-linked actors, underscoring the advisory's placement of this campaign within a wider theft trend.

Keep Reading