The North Korean hacking group WaterPlum, also known as Contagious Interview, has stolen at least $10.7 million in cryptocurrency by posing as recruiters for legitimate AI, crypto, and NFT companies. According to a joint advisory from authorities in Japan, Germany, Australia, and the US, the campaign targeted software developers and IT professionals globally between December 2025 and July 2026. The group lured victims through social media and freelance platforms, instructing them to download malicious files disguised as coding assignments or video-conferencing fixes. Once executed, these files deployed remote-access trojans and infostealing malware, resulting in infections on at least 30,000 devices across more than 100 countries. Authorities reported that funds or account credentials were extracted from over 7,000 cryptocurrency wallets during this period.

Japanese and US officials assess that WaterPlum actors operate under North Korea’s Munitions Industry Department, linking the cyber operations to broader efforts to place IT workers inside foreign companies. Beyond direct theft, the stolen identity documents enable North Korean operatives to impersonate victims for income generation or extortion. The advisory highlighted specific incidents, including a rejected application at a Japanese crypto exchange due to resume discrepancies and a case involving Consensys, which terminated access for a North Korea-linked consultant after discovering the threat but confirmed no asset theft occurred. This campaign continues North Korea’s persistent use of cryptocurrency theft for fundraising, following previous high-profile incidents such as the $1.5 billion Bybit theft attributed to Pyongyang in February 2025.