A North Korean hacking group known as WaterPlum, also called Contagious Interview, has stolen at least $10.7 million by impersonating recruiters for legitimate cryptocurrency, artificial intelligence, and non-fungible token companies. The group targeted software developers and IT professionals worldwide through social media platforms, online job boards, gig work platforms, and freelance marketplaces.
According to a joint advisory from Japan, Germany, Australia, and the US, WaterPlum focused on web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. Victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors during the recruitment process.
Once attackers gained backdoor access to victims' computers, they deployed remote-access trojans and information-stealing malware to extract sensitive data and cryptocurrency credentials. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries, compromising over 7,000 cryptocurrency wallets.
The campaign extends beyond direct theft. Stolen identity documents allow North Korean IT workers to impersonate victims and secure employment, while sensitive information can be used for extortion. Authorities have linked WaterPlum actors to North Korea's Munitions Industry Department and a broader operation placing IT workers inside foreign companies.
The advisory documented a case in which a suspected North Korean IT worker applied for an engineering position at a Japanese cryptocurrency exchange using a forged resume. The exchange rejected the applicant after discovering discrepancies during the interview, including an inability to explain listed technical skills.
In July, Consensys engaged a North Korea-linked developer as a consultant before discovering the threat and terminating access. An investigation found no theft of assets, data breaches, malicious code deployment, or impact on user safety.
The scheme represents the latest cryptocurrency theft attributed to North Korea, which has faced years of warnings and enforcement actions. US authorities have warned about North Korean undercover IT workers since at least 2018.


