North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
A North Korea-linked hacking group known as WaterPlum (also called Contagious Interview) posed as recruiters for crypto, AI and NFT firms to infect job seekers with malware, siphoning at least $10.7 million in cryptocurrency. Authorities say the campaign compromised at least 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 wallets between December 2025 and July 2026.

Why It Matters
The operation highlights how state-linked cyber actors exploit legitimate hiring channels to target skilled IT workers, creating pathways not only for direct theft but also for deeper infiltration of organizations. Those tactics complicate efforts to secure corporate networks and crypto assets amid ongoing North Korean fundraising through cybercrime.
Key Facts
- Group: WaterPlum (aka Contagious Interview)
- Stolen funds: $10.7 million in cryptocurrency
- Infected devices: At least 30,000 devices
- Countries affected: More than 100 countries
- Wallets impacted: Funds or credentials extracted from over 7,000 wallets (Dec 2025–Jul 2026)
A multi-national advisory from Japan, Germany, Australia and the United States attributes a global malware campaign to North Korea-linked actors operating under the name WaterPlum, or Contagious Interview. According to the advisory, the group impersonated recruiters from legitimate AI, cryptocurrency and NFT companies to target software developers, web designers and other IT professionals. Victims were contacted through social media, online job platforms, gig sites and freelance marketplaces.
During the bogus recruitment process, the attackers sent files presented as coding tests or fixes for video-conferencing issues and instructed candidates to download and run them. Once executed, those files installed remote-access trojans and information-stealing malware that allowed the actors to exfiltrate credentials and cryptocurrency. The advisory says the campaign led to at least $10.7 million in stolen crypto and compromised devices across more than 100 countries.
Authorities linked WaterPlum’s activity to a broader North Korean effort that places IT workers inside foreign companies, with Japanese and U.S. assessments indicating ties between WaterPlum actors and some North Korean IT workers operating under the Munitions Industry Department. Successful compromises of individual developers also provided opportunities for the actors to move laterally and target the organizations that employed the compromised individuals.
The advisory cited specific incidents illustrating the methods and risks: a suspected North Korean IT worker applied to a Japanese crypto exchange using a forged resume and was rejected after inconsistencies emerged during the interview process; and in July, Consensys reportedly engaged a developer later linked to North Korea, then terminated access after discovering the connection — with its investigation finding no asset theft or malicious code deployment. The bulletin places this campaign in the context of a long-running North Korean reliance on cryptocurrency theft for revenue, noting past attributions such as the FBI’s finding that North Korea was behind a $1.5 billion Bybit theft in February 2025.
Keep Reading

No Dogs in Space is back to feed your need for obsessive music history

Elon Musk’s latest Boring Company pitch involves a Hyperloop between Austin and San Antonio

AI fears burst onto Trump-Xi agenda, but challenges abound

World model companies are keeping a lot of secrets
Original source: Cointelegraph