North Korean Fake Recruiters Infect 30,000 Devices, Steal $10.7M in Crypto

North Korean Fake Recruiters Infect 30,000 Devices, Steal $10.7M in Crypto

What happened

North Korean hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate cryptocurrency, AI, and NFT companies. The group infected at least 30,000 devices across more than 100 countries by targeting unsuspecting job seekers.

WaterPlum, also known as Contagious Interview, specifically targeted software developers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The group operated under a scheme disclosed in a joint cybersecurity advisory from authorities in Japan, Germany, Australia, and the United States.

Key numbers

  • At least 30,000 devices infected across more than 100 countries.
  • At least $10.7 million stolen.
  • Funds or account credentials extracted from over 7,000 cryptocurrency wallets.
  • The campaign ran between December 2025 and July 2026.

How the scam worked

WaterPlum lured victims through social media platforms, online job platforms, gig work platforms, and freelance marketplaces. During the recruitment process, victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors.

Once the hackers obtained backdoor access to a victim's computer, they used remote-access trojans and infostealing malware to steal sensitive data and cryptocurrency. A cryptocurrency wallet is a digital tool that stores the keys needed to access and transfer digital assets like Bitcoin or Ether.

The advisory also links WaterPlum to North Korea's broader campaign of placing IT workers inside foreign companies. Japanese and US authorities assess that WaterPlum actors and some North Korean IT workers operate under North Korea's Munitions Industry Department.

Real-world cases

The advisory described a case in which a suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange using a forged resume. The exchange rejected the applicant after finding discrepancies during the interview, including an inability to explain the skills listed on the resume in detail.

A more recent case occurred in July, when Cointelegraph reported that Consensys had unknowingly engaged a North Korea-linked developer as a consultant. The company said it terminated the person's access after discovering the threat, and an investigation found no theft of assets or data and no impact on user safety.

Why it matters

The damage from these attacks extends beyond stolen cryptocurrency. Stolen identity documents allow North Korean IT workers to impersonate victims and earn income. Sensitive information obtained from victims could also be used for extortion.

This campaign is the latest example of North Korea's persistent use of cryptocurrency theft to raise funds, despite years of warnings and enforcement actions. US authorities have warned about North Korea's undercover IT workers since at least 2018.

What is still unclear

The full scale of WaterPlum's operations and the total number of victims may be larger than what has been publicly disclosed. The exact methods used by the group to launder stolen funds have not been detailed in the advisory.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!