Authorities say a North Korean cyber group known as WaterPlum used fake recruiting approaches to target developers and other IT workers tied to crypto, AI and NFT companies, infecting at least 30,000 devices in more than 100 countries.
The operation, also known as Contagious Interview, allegedly stole at least $10.7 million and extracted funds or account credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. Investigators said the campaign relied on malware disguised as job-related tests or technical fixes during the hiring process.
Fake hiring process used as the delivery method
According to the advisory, the group posed as recruiters for legitimate companies and also operated through recruiting services. Its main targets were software developers, web designers, engineers and other specialists working in cryptocurrency, blockchain and Web3 fields, though the impersonated employers also included AI and NFT businesses.
Victims were approached through social media, online job boards, gig platforms and freelance marketplaces. During the supposed interview process, job seekers were told to download and run files presented as coding assignments or as fixes for video-conferencing problems, giving the attackers an opening to compromise their systems.
Malware enabled theft and long-term access
Once the malicious files were executed, authorities said WaterPlum used backdoor access along with remote-access trojans and infostealing malware to take sensitive data and cryptocurrency. The campaign was not limited to direct theft from individuals, as infected devices could also provide a path into the companies that later employ those developers.
Investigators said the group extracted funds or credentials from more than 7,000 crypto wallets during the period identified in the advisory. The total losses were reported at no less than $10.7 million.
Part of a broader North Korean IT worker effort
The advisory links WaterPlum to North Korea’s wider effort to place IT workers inside foreign companies. Authorities said stolen identity documents from victims can be used by North Korean operatives to impersonate them and earn income through remote work.
Sensitive information collected in the campaign could also be used for extortion, according to investigators. The report also described cases in which North Korean IT workers applied for roles at crypto exchanges using forged resumes, with some applicants rejected or later terminated after discrepancies were uncovered.
What authorities have confirmed so far
Authorities described the campaign as an extension of North Korea’s continued use of cryptocurrency-related theft to generate funds despite prior warnings and enforcement actions. The confirmed scope in the advisory covers at least 30,000 infected devices spread across more than 100 countries.
The latest findings indicate the operation remained active through at least July 2026. Based on the advisory, the immediate confirmed risk is twofold: direct theft from targeted professionals and the possibility that compromised job seekers could become an entry point into their employers’ systems.
Source: cointelegraph.com