The North Korean hacking group WaterPlum, also known as Contagious Interview, has stolen at least $10.7 million in cryptocurrency by posing as recruiters for legitimate AI, crypto, and NFT companies. According to a joint advisory from authorities in Japan, Germany, Australia, and the US, the campaign targeted software developers and IT professionals globally between December 2025 and July 2026. The group lured victims through social media and freelance platforms, instructing them to download malicious files disguised as coding assignments or video-conferencing fixes. Once executed, these files deployed remote-access trojans and infostealing malware, resulting in infections on at least 30,000 devices across more than 100 countries. Authorities reported that funds or account credentials were extracted from over 7,000 cryptocurrency wallets during this period.
Japanese and US officials assess that WaterPlum actors operate under North Korea’s Munitions Industry Department, linking the cyber operations to broader efforts to place IT workers inside foreign companies. Beyond direct theft, the stolen identity documents enable North Korean operatives to impersonate victims for income generation or extortion. The advisory highlighted specific incidents, including a rejected application at a Japanese crypto exchange due to resume discrepancies and a case involving Consensys, which terminated access for a North Korea-linked consultant after discovering the threat but confirmed no asset theft occurred. This campaign continues North Korea’s persistent use of cryptocurrency theft for fundraising, following previous high-profile incidents such as the $1.5 billion Bybit theft attributed to Pyongyang in February 2025.
The scale of the WaterPlum operation demonstrates how social engineering targeting individual developers serves as a critical vector for institutional compromise. By infecting 30,000 devices, the group not only extracted immediate financial value but also established footholds within organizations employing these individuals. This dual-purpose attack strategy highlights a significant gap in current cybersecurity postures, where personal device hygiene is often treated separately from corporate network security. The ability of attackers to pivot from individual job seekers to organizational infiltration suggests that traditional perimeter defenses are insufficient against threats originating from trusted external contractors or employees using compromised personal hardware.
Regulatory and compliance frameworks must now address the intersection of labor practices and cybersecurity risk. The involvement of the Munitions Industry Department indicates state-sponsored coordination, elevating these incidents from criminal activity to national security concerns. Firms hiring remote technical talent face operational risks if they do not implement rigorous verification processes beyond standard background checks. The Consensys incident illustrates that even with detection mechanisms, the potential for data exfiltration remains high until access is revoked. Consequently, institutions should prioritize monitoring for anomalous behavior in remote access logs and enforce stricter segmentation between personal development environments and production systems to mitigate the spread of malware introduced through recruitment channels.


