North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters for legitimate crypto and AI companies and infecting job seekers with malware. A joint advisory from Japan, Germany, Australia, and the US says the group mainly targeted software developers, engineers, and crypto/Web3 specialists worldwide through social media, job boards, gig platforms, and freelance marketplaces. Victims were tricked into downloading malicious files disguised as coding tasks or fixes for video-call issues. After gaining access, WaterPlum used remote-access trojans and infostealers to steal data and cryptocurrency, and could also use compromised devices to infiltrate employers. The campaign infected at least 30,000 devices in over 100 countries and drained credentials or funds from more than 7,000 crypto wallets between December 2025 and July 2026. Authorities also link the group to North Korea’s wider effort to place IT workers inside foreign companies.
