North Korean hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate crypto and AI companies, attacking unsuspecting job seekers with malware.
North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.
Cointelegraph by Felix Ng
Publisher Cointelegraph
Sep 21, 2026 at 1:42 AM UTC · 2 min read

The group, also known as Contagious Interview, targets software developers and IT professionals worldwide, according to a joint advisory from Japan, Germany, Australia and the US. Authorities said the fake recruiters impersonated legitimate AI, cryptocurrency or non-fungible token (NFT) companies and also used recruiting services.
“The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” they added.
The advisory also links WaterPlum to North Korea’s broader campaign of placing IT workers inside foreign companies, with Japanese and US authorities assessing that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department.
According to the advisory, WaterPlum lured job seekers through social media platforms, online job platforms, gig work platforms or freelance marketplaces. During the recruitment process, victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors.
Article Intelligence
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
