Key Highlights
- North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate crypto and AI companies to target software developers and IT professionals worldwide.
- The campaign infected over 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
- A joint advisory from Japan, Germany, Australia, and the United States links WaterPlum to North Korea’s Munitions Industry Department and its broader strategy of placing undercover IT workers inside foreign organizations.
Global Advisory Exposes Sophisticated Recruitment Fraud
A joint cybersecurity advisory issued by authorities in Japan, Germany, Australia, and the United States has detailed a sprawling operation by the North Korean hacking group WaterPlum, also tracked as Contagious Interview. The group masqueraded as recruiters for legitimate artificial intelligence, cryptocurrency, and non-fungible token (NFT) companies, leveraging social media platforms, online job boards, gig work sites, and freelance marketplaces to lure victims. According to the advisory, the primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The operation has resulted in the theft of at least $10.7 million, marking a significant escalation in North Korea’s use of social engineering to fund its weapons programs.
Malware Deployment via Fake Coding Assignments
The attack chain relied on tricking job seekers into downloading and executing malicious files disguised as coding assignments or fixes for video-conferencing errors. Once executed, the malware provided the threat actors with backdoor access to the victim’s computer. WaterPlum operators then deployed remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. The advisory notes that successful infections create downstream risks, enabling WaterPlum actors to infiltrate the organizations that employ the compromised developers, thereby extending the blast radius beyond individual freelancers to corporate networks.
Connection to North Korean IT Worker Infiltration
The advisory explicitly links WaterPlum’s activities to North Korea’s broader campaign of placing IT workers inside foreign companies under false pretenses. Japanese and U.S. authorities assess that WaterPlum actors and certain North Korean IT workers operate under the direction of the country’s Munitions Industry Department. This dual-track approach—stealing cryptocurrency directly while simultaneously building a workforce of impersonators—amplifies the regime’s revenue generation. Stolen identity documents allow North Korean operatives to impersonate legitimate developers, securing employment and income, while sensitive personal data harvested during intrusions creates opportunities for extortion.
Recent Incidents Highlight Ongoing Threat
The advisory cites concrete examples of the infiltration tactic. In one case, a suspected North Korean IT worker applied for an engineering role at a Japanese cryptocurrency exchange using a forged resume; the applicant was rejected after failing to demonstrate the claimed skills during the interview. More recently, in July, Cointelegraph reported that blockchain software company Consensys had unknowingly engaged a North Korea-linked developer as a consultant. Consensys confirmed it terminated the contractor’s access upon discovering the threat, stating an investigation found no theft of assets or data, no malicious code deployment, and no impact on user safety. These incidents underscore the persistent difficulty organizations face in vetting remote technical talent.
Why This Matters
The WaterPlum campaign represents the latest evolution in North Korea’s long-standing reliance on cryptocurrency theft to circumvent international sanctions and fund its nuclear and ballistic missile programs. The Federal Bureau of Investigation (FBI) previously attributed the $1.5 billion theft from the Bybit exchange in February 2025 to North Korean actors. U.S. authorities have issued warnings about the regime’s undercover IT worker scheme since at least 2018. The convergence of direct financial theft, supply chain compromise via compromised developers, and strategic workforce infiltration signals a mature, well-resourced threat ecosystem. For the cybersecurity industry and any organization hiring remote technical talent, the advisory serves as a critical reminder that identity verification and device trust cannot be assumed based solely on a resume or interview performance.
Frequently Asked Questions
What is WaterPlum and how does it operate?
WaterPlum, also known as Contagious Interview, is a North Korean state-sponsored hacking group. It operates by posing as recruiters from legitimate AI, crypto, and NFT companies on job platforms. The group tricks software developers and IT professionals into downloading malware disguised as coding tests or software fixes, gaining backdoor access to steal cryptocurrency, credentials, and sensitive data.
How can job seekers protect themselves from such recruitment scams?
Job seekers should verify the legitimacy of recruiters and companies through independent channels before downloading any files. Be wary of unsolicited offers, requests to execute code as part of an interview process, or pressure to install specific video-conferencing software or “fixes.” Use endpoint detection and response (EDR) solutions and maintain strict separation between personal and work devices.
What are the implications for companies hiring remote developers?
Companies face the risk of inadvertently hiring North Korean operatives using stolen identities, which can lead to intellectual property theft, infrastructure compromise, and regulatory violations. The Consensys incident demonstrates that even sophisticated firms can be deceived. Organizations must implement rigorous identity verification, background checks, technical assessments that cannot be easily faked, and continuous monitoring of contractor activity.

