North Korean fake recruiters infected 30,000 devices and stole at least $10.7 million in crypto
A North Korean hacking group known as WaterPlum, or Contagious Interview, posed as recruiters for legitimate crypto and AI companies, tricked job seekers into running malware, and pulled at least $10.7 million from crypto wallets. For high-risk operators, the useful bit is simple: recruitment channels are now an attack surface, not just a hiring function.
- According to a joint advisory from Japan, Germany, Australia and the US, WaterPlum targeted software developers and IT professionals worldwide by impersonating legitimate AI, cryptocurrency or NFT companies, and in some cases using recruiting services. The stated primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.
- The group used social media platforms, online job platforms, gig work platforms and freelance marketplaces to reach victims. During the hiring process, targets were told to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors, which then gave the attackers backdoor access to their computers.
- Once inside, WaterPlum used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. The advisory says the group infected at least 30,000 devices in more than 100 countries, and extracted funds or account credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
- The fallout went beyond direct wallet theft. Stolen identity documents could be used by North Korean IT workers to impersonate victims and earn income, while sensitive information could support extortion. The advisory also links WaterPlum to North Korea’s broader effort to place IT workers inside foreign companies, with Japanese and US authorities assessing that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department.
- The case fits a pattern that keeps showing up in crypto: employment fraud as an entry point, followed by malware, credential theft and then money movement. The advisory cited a Japanese crypto exchange that rejected a suspected North Korean IT worker after interview inconsistencies, and noted a July case in which Consensys terminated access for a North Korea-linked developer after discovering the threat.
The wider backdrop is familiar enough to be annoying: the FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025, and the same playbook keeps resurfacing in different forms. For PSPs, exchanges and other high-risk merchants, the hiring funnel is now part of the security perimeter.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!