Key Takeaways
- Cybercriminals linked to North Korea reportedly compromised over 30,000 devices spanning more than 100 nations through fraudulent employment opportunities.
- International investigators confirmed that more than 7,000 digital currency wallets were breached in the operation.
- A minimum of $10.7 million in cryptocurrency was successfully exfiltrated and routed to North Korea.
- The threat group known as WaterPlum specifically pursued software engineers and technology professionals with fabricated positions at cryptocurrency, artificial intelligence, and NFT enterprises.
- Targets were frequently instructed to execute malicious software masquerading as technical assessments or solutions for video conferencing issues.
A cybercrime operation attributed to North Korea employed deceptive hacking group recruiting tactics to compromise more than 30,000 computer systems and pilfer at least $10.7 million worth of digital currency, based on a coordinated international security alert.
The criminal organization, identified as WaterPlum and alternatively as Contagious Interview, focused on software programmers and information technology specialists in over 100 nations.
Law enforcement agencies from the United States, Japan, Australia, and Germany revealed that these cybercriminals impersonated talent acquisition professionals, dangling positions at seemingly authentic cryptocurrency, blockchain, artificial intelligence, and NFT organizations.
According to reports, more than 7,000 digital asset wallets were successfully infiltrated during the period spanning December 2025 through July 2026.
Bogus Cryptocurrency Employment Opportunities Deliver Malicious Software
WaterPlum made contact with targets via social networking platforms, employment portals, independent contractor websites, and professional recruiting services.
The perpetrators advertised appealing career prospects before advancing candidates through a fabricated technical screening procedure.
Targets were subsequently instructed to retrieve documents or execute programming scripts presented as mandatory coding evaluations.
In additional scenarios, job candidates received instructions to deploy applications purportedly required to resolve technical difficulties with virtual meeting platforms.
These files actually harbored malicious code engineered to grant unauthorized system access to the attackers.
Investigators documented multiple malware variants deployed throughout this campaign, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Following successful installation, the malicious software possessed capabilities to harvest browser authentication credentials, clipboard contents, screen captures, keystroke recordings, and locally stored documents.
Cryptocurrency private keys and wallet recovery phrases represented primary objectives.
Cybercriminals Pilfer $10.7 Million in Digital Assets
Government authorities confirmed WaterPlum successfully extracted financial assets or account access credentials from over 7,000 cryptocurrency storage wallets.
A confirmed minimum of $10.71 million in stolen digital currency was successfully transferred to North Korean destinations, according to the official advisory.
These intrusions potentially generate broader cybersecurity vulnerabilities for organizations that employ victimized software developers.
Following initial compromise of an employee’s workstation, stolen authentication credentials may potentially enable unauthorized access to corporate infrastructure, client information, or proprietary business intelligence.
Personal identification documentation represented another significant target category.
Officials stated that exfiltrated passport scans and government-issued identification could facilitate North Korean technology workers impersonating legitimate individuals when seeking employment positions abroad.
Compromised information could additionally serve extortion purposes.
Investigators noted that certain WaterPlum operatives deployed artificial intelligence-powered facial replacement technology during virtual interviews before disabling video feeds and citing technical malfunctions.
North Korean Technology Worker Initiative Persists
The security advisory connected WaterPlum to North Korea’s broader strategic initiative to embed technology workers within international corporations.
American and Japanese government analysts assess that WaterPlum participants and certain North Korean IT personnel function under an organizational unit affiliated with the nation’s military-industrial complex.
One individual suspected of North Korean ties recently submitted an application for a software engineering position at a Japanese cryptocurrency trading platform utilizing falsified credentials.
The candidate was declined after interview panel members detected inconsistencies between the applicant’s documented expertise and their capacity to articulate the specified technical competencies.
ConsenSys additionally revealed in July that the organization had inadvertently contracted a North Korea-affiliated programmer as an external consultant.
The corporation revoked the individual’s system access following discovery of the connection and announced that forensic examination revealed no evidence of asset theft, data exfiltration, malicious code injection, or compromise of user security.
Government authorities are recommending job applicants refrain from executing code or downloading materials from unverified recruiters and immediately disconnect potentially compromised equipment from network connectivity.





