North Korean cyber group WaterPlum posed as recruiters for legitimate crypto and AI companies and stole at least $10.7 million in cryptocurrency, according to Cointelegraph and a joint advisory issued by authorities in Japan, Germany, Australia and the United States. The advisory said the campaign infected at least 30,000 devices in more than 100 countries.
Fake job offers targeted developers and IT workers
WaterPlum, also known as Contagious Interview, targeted software developers and IT professionals around the world. Authorities said the group impersonated legitimate AI, cryptocurrency and non-fungible token, or NFT, companies and also used recruiting services to approach victims.
The advisory said, 「The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.」
According to the advisory, WaterPlum lured job seekers through social media platforms, online job platforms, gig work platforms and freelance marketplaces. During the hiring process, victims were told to download and run malicious files presented as coding assignments or fixes for video-conferencing errors.
Backdoor access led to theft of data and crypto
Once the attackers gained backdoor access to a victim’s computer, they used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency.
The advisory said successful infections also created openings for WaterPlum actors to infiltrate organizations that employed the targeted developers.
Between December 2025 and July 2026, the group extracted funds or account credentials from more than 7,000 cryptocurrency wallets while infecting at least 30,000 devices across more than 100 countries.
Advisory ties the operation to North Korea’s overseas IT worker campaign
The joint advisory also linked WaterPlum to North Korea’s broader effort to place IT workers inside foreign companies. Japanese and US authorities assessed that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department.
The damage, the advisory said, goes beyond stolen cryptocurrency. Stolen identity documents can allow North Korean IT workers to impersonate victims and earn income, while sensitive information could also be used for extortion.
Japanese crypto exchange rejected applicant using forged resume
The advisory described one case in which a suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange with a forged resume. The exchange rejected the applicant after spotting discrepancies during the interview, including an inability to explain in detail the skills listed on the resume.
Cointelegraph also cited a July case involving Consensys
In a more recent case, Cointelegraph reported in July that Consensys had unknowingly engaged a North Korea-linked developer as a consultant. The company told Cointelegraph it terminated the person’s access after discovering the threat. Its investigation found no theft of assets or data, no malicious code deployment and no impact on user safety.
Latest example of North Korea’s use of crypto theft
The reported campaign is the latest example of North Korea’s continued use of cryptocurrency theft to raise funds. The FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025, while US authorities have warned about undercover North Korean IT workers since at least 2018.

