North Korean Group WaterPlum Steals $10.7M by Posing as Recruiters in Crypto and AI Fields

North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate cryptocurrency and AI companies. According to a joint advisory from authorities in Japan, Germany, Australia, and the US, the attackers targeted IT job seekers worldwide, infecting their devices with malware to steal cryptocurrency and sensitive information.
Attack Methods and Targets of WaterPlum
WaterPlum targeted web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The group attracted victims through social media, job search platforms, gig job websites, and freelance marketplaces.
During the recruitment process, victims were asked to download and run malicious files disguised as coding assignments or fixes for video conferencing issues.
Once access to victims' devices was gained, attackers used remote-access trojans and infostealing malware to exfiltrate cryptocurrencies and sensitive data.
Scale and Impact of the Attacks
WaterPlum infected at least 30,000 devices across more than 100 countries and extracted credentials or funds from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
Beyond financial theft, stolen identity documents enable North Korean IT workers to impersonate victims for income and create risks of extortion and sensitive data leaks.
The advisory linked WaterPlum to a broader North Korean effort to embed IT workers in foreign companies, with Japanese and US authorities assessing these actors operate under North Korea’s Munitions Industry Department.
Examples of Revealed Incidents
One case involved a suspected North Korean IT worker applying for an engineering job at a Japanese crypto exchange using a forged resume. The applicant was rejected after interview inconsistencies and inability to explain listed skills.
In July, Cointelegraph reported that Consensys unintentionally engaged a North Korean-linked developer as a consultant, terminating access upon discovery. An investigation found no asset or data theft, malicious code deployment, or user safety impact.
Context and Evolution of the Threat
This campaign exemplifies North Korea’s continuous use of cryptocurrency theft to generate funds despite longstanding warnings and enforcement actions.
In February 2025, the FBI attributed a $1.5 billion theft from the crypto exchange Bybit to North Korean actors.
Since at least 2018, US authorities have warned about North Korea’s covert IT workers, emphasizing the scale and persistence of these cybersecurity threats.
Why it matters
This news highlights the extensive and systematic operations of the North Korean hacking group WaterPlum, which employs social engineering tactics to steal cryptocurrency and valuable data. The vulnerability of IT professionals seeking employment underscores the critical importance of cybersecurity awareness and caution when engaging with potential recruiters. Beyond financial losses, attackers gain access to personal data, enabling extortion and illicit income through impersonation. The case also deepens understanding of geopolitical risks and the scale of international cyberattacks linked to North Korea, emphasizing the need for coordinated multi-national efforts to counter such threats.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗