TLDR
- North Korea-linked hackers allegedly infected more than 30,000 devices in over 100 countries using fake job offers.
- Authorities said more than 7,000 cryptocurrency wallets were compromised.
- At least $10.7 million in crypto was stolen and transferred to North Korea.
- The WaterPlum group targeted developers and IT workers through fake roles at crypto, AI and NFT companies.
- Victims were often asked to download malicious files disguised as coding tests or fixes for video-call problems.
A North Korea-linked hacking group used fake recruitment campaigns to infect more than 30,000 devices and steal at least $10.7 million in cryptocurrency, according to a joint international advisory.
INTEL: North Korea-linked hackers infected 30,000+ devices across 100+ countries, compromised data from 7,000+ crypto wallets and received at least $10.7 million into wallets they controlled, Japanese and U.S. authorities say pic.twitter.com/cnfsYvwBgp
— Solid Intel 📡 (@solidintel_x) September 18, 2026
The group, known as WaterPlum and Contagious Interview, targeted software developers and IT professionals across more than 100 countries.
Authorities from the U.S., Japan, Australia and Germany said the hackers posed as recruiters offering jobs at legitimate-looking crypto, blockchain, AI and NFT companies.
More than 7,000 cryptocurrency wallets were reportedly compromised between December 2025 and July 2026.
Fake Crypto Jobs Used to Spread Malware
WaterPlum approached victims through social media, job websites, freelance marketplaces and recruitment platforms.
The attackers presented attractive employment opportunities before moving candidates into a fake technical interview process.
Victims were then asked to download files or run code as part of supposed programming assignments.
In other cases, applicants were told they needed to install software to fix problems with video-conferencing tools.
The files instead contained malware designed to give attackers access to the victim’s computer.
Authorities identified several malware families used in the campaign, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
Once installed, the malware could collect browser login credentials, clipboard data, screenshots, keystrokes and files stored on the device.
Crypto private keys and wallet seed phrases were also targeted.
Hackers Steal $10.7 Million in Crypto
Authorities said WaterPlum extracted funds or account credentials from more than 7,000 cryptocurrency wallets.
At least $10.71 million in stolen cryptocurrency was transferred to North Korea, according to the advisory.
The attacks could also create wider security risks for companies employing targeted developers.
Once attackers gain access to a worker’s computer, stolen credentials can potentially be used to access employer systems, customer information or company data.
Personal identity documents were another target.
Authorities said stolen passport scans and identification documents could be used by North Korean IT workers to impersonate victims while applying for jobs overseas.
Stolen data could also be used for extortion.
Investigators said some WaterPlum operators used AI face-swapping technology during online interviews before turning off their cameras and blaming technical problems.
North Korean IT Worker Campaign Continues
The advisory linked WaterPlum to North Korea’s wider effort to place IT workers inside foreign companies.
U.S. and Japanese authorities assess that WaterPlum actors and some North Korean IT workers operate under a unit connected to the country’s military industry apparatus.
One suspected North Korean IT worker recently applied for an engineering role at a Japanese crypto exchange using a forged resume.
The applicant was rejected after interviewers identified differences between the person’s stated experience and their ability to explain the listed technical skills.
Consensys also disclosed in July that it had unknowingly hired a North Korea-linked developer as a consultant.
The company terminated the person’s access after discovering the connection and said an investigation found no asset theft, stolen data, malicious code or effect on user safety.
Authorities are advising job seekers to avoid running code or downloading files from recruiters they cannot verify and to disconnect potentially infected devices from the internet immediately.







