Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

North Korean Hacking Group WaterPlum Steals $10.7M in Crypto Through Fake Recruiter Scheme

A North Korean hacking group posing as recruiters for legitimate crypto and AI companies infected 30,000 devices across more than 100 countries and stole at least $10.7 million in cryptocurrency, according to a joint advisory from Japan, Germany, Australia, and the US.
1 hour ago 10 views
North Korean Hacking Group WaterPlum Steals $10.7M in Crypto Through Fake Recruiter Scheme

A North Korean hacking group known as WaterPlum, also called Contagious Interview, has stolen at least $10.7 million by impersonating recruiters for legitimate cryptocurrency, artificial intelligence, and non-fungible token companies. The group targeted software developers and IT professionals worldwide through social media platforms, online job boards, gig work platforms, and freelance marketplaces.

According to a joint advisory from Japan, Germany, Australia, and the US, WaterPlum focused on web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. Victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors during the recruitment process.

Once attackers gained backdoor access to victims' computers, they deployed remote-access trojans and information-stealing malware to extract sensitive data and cryptocurrency credentials. Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries, compromising over 7,000 cryptocurrency wallets.

The campaign extends beyond direct theft. Stolen identity documents allow North Korean IT workers to impersonate victims and secure employment, while sensitive information can be used for extortion. Authorities have linked WaterPlum actors to North Korea's Munitions Industry Department and a broader operation placing IT workers inside foreign companies.

The advisory documented a case in which a suspected North Korean IT worker applied for an engineering position at a Japanese cryptocurrency exchange using a forged resume. The exchange rejected the applicant after discovering discrepancies during the interview, including an inability to explain listed technical skills.

In July, Consensys engaged a North Korea-linked developer as a consultant before discovering the threat and terminating access. An investigation found no theft of assets, data breaches, malicious code deployment, or impact on user safety.

The scheme represents the latest cryptocurrency theft attributed to North Korea, which has faced years of warnings and enforcement actions. US authorities have warned about North Korean undercover IT workers since at least 2018.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $81,401.19+1.15% EthereumETH $2,665.80+2.97% Tether USDUSDT $0.9994+0.03% BNBBNB $777.94+3.36% XRPXRP $1.42+2.80% USDCUSDC $0.9998-0.02% SolanaSOL $111.60+2.65% TRONTRX $0.3431+0.89% HyperliquidHYPE $93.04+2.35% ZcashZEC $1,518.29+3.79%
Prices by Coinranking. Informational only.