-
A North Korean hacking group called WaterPlum pretended to be job recruiters at crypto and AI companies to trick developers into downloading malware.
-
The group infected over 30,000 devices in more than 100 countries and drained funds from over 7,000 crypto wallets.
-
Authorities from Japan, Germany, Australia, and the US have now issued a joint warning about the group’s growing operations.
A North Korean hacking group just pulled off a massive cyber con. They used fake job offers to spread malware and steal millions in crypto.
The group is called WaterPlum, also known as Contagious Interview. They targeted software developers and IT professionals around the world. Their method was simple but very effective. They pretended to be recruiters at real crypto, AI, and NFT companies.
Then they tricked job seekers into downloading harmful files. According to a joint advisory from Japan, Germany, Australia, and the US, the group stole at least $10.7 million this way.
Fake Jobs, Real Damage
WaterPlum did not randomly pick their victims. They went after specific people with specific skills. “The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” the advisory stated.
The group found their victims on social media, online job boards, gig platforms, and freelance marketplaces. Once they got someone interested in a fake job, they moved fast. They asked the victim to download a file. The file looked like a coding test or a fix for a video call problem. In reality, it was malware.
North Korean hackers have also been linked to malicious packages planted across open-source ecosystems, showing how the same threat actors can target developers through trusted software channels.
After the victim ran the file, WaterPlum got backdoor access to their computer. From there, they used remote-access tools and data-stealing software. These tools let them pull out sensitive information and crypto funds quietly. The victim often had no idea anything had happened.
The group infected at least 30,000 devices across more than 100 countries. Between December 2025 and July 2026, they pulled funds or account details from over 7,000 crypto wallets. The total financial damage came to at least $10.7 million.
But the damage did not stop at stolen crypto. WaterPlum also collected identity documents from victims. North Korean IT workers then used those documents to impersonate real people. They applied for jobs at foreign companies, earned salaries, and sent that money back to North Korea. The advisory also warned that stolen personal information could be used for extortion.
A Pattern of Deception With Real-World Cases
The advisory shared a real example of how bold these operations have become. A suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange. He used a fake resume. During the interview, the company noticed problems. He could not explain the skills listed on his own resume. The exchange rejected him.
A more recent case happened in July. Cointelegraph reported that Consensys, a major blockchain software company, had unknowingly hired a North Korea-linked developer as a consultant. The company said it ended their access as soon as it found out. An investigation found no stolen assets or data, no harmful code added to systems, and no risk to users.
These cases show how WaterPlum blends two operations together. On one side, they spread malware through fake job offers. On the other side, they place real (but fake-identity) workers inside companies. Both tactics serve the same goal. They funnel money back to North Korea.
The advisory also links WaterPlum to North Korea’s Munitions Industry Department. Japanese and US authorities both concluded that WaterPlum actors and some North Korean IT workers operate under this government body.
Not a New Problem
WaterPlum’s latest campaign is part of a much longer pattern. North Korea has been using crypto theft to raise money for years. US authorities have been warning about undercover North Korean IT workers since at least 2018. The warnings have not stopped the activity.
Earlier this year, the FBI blamed North Korea for the $1.5 billion Bybit hack in February 2025. That was one of the largest crypto heists ever recorded. WaterPlum’s $10.7 million campaign adds to a growing total that experts say funds North Korea’s weapons programs.
For everyday job seekers, the warning is clear. Be very careful about job offers that come through social media or freelance sites. Think twice before downloading any file sent during a hiring process. If a recruiter asks you to run a setup file or install software just to apply, that is a major red flag.
For companies, the risk is just as real. An infected developer can become a door into the whole organization. WaterPlum has shown it will use that access. Hiring teams need to verify identities carefully and watch for signs of deception during interviews, including an inability to back up claimed skills.