Home Cybersecurity SKN | North Korean Fake Recruiters Infect 30,000 Devices and Steal $10.7M in Crypto
Cybersecurity

SKN | North Korean Fake Recruiters Infect 30,000 Devices and Steal $10.7M in Crypto

Share
Share

Key Points

  • North Korean-linked cyber group WaterPlum targeted developers and IT professionals with fake recruitment offers impersonating legitimate cryptocurrency, AI and NFT companies.
  • Authorities said the campaign infected at least 30,000 devices across more than 100 countries and extracted funds or credentials from more than 7,000 cryptocurrency wallets.
  • The operation highlights how fake technical assignments and employment opportunities can provide attackers with both direct access to digital assets and potential entry points into companies employing targeted developers.

WaterPlum Targets Developers Through Fake Job Offers

North Korean cyber group WaterPlum has used fraudulent recruitment campaigns to target software developers, web designers and cryptocurrency professionals, stealing at least $10.7 million in cryptocurrency while compromising thousands of devices.

WaterPlum, also known as Contagious Interview, allegedly posed as recruiters for legitimate companies operating in artificial intelligence, cryptocurrency and non-fungible tokens. The group also used legitimate recruiting services and employment platforms to reach potential victims.

A joint cybersecurity advisory from authorities in Japan, Germany, Australia and the United States identified developers and IT specialists, particularly those working in cryptocurrency, blockchain and Web3, as primary targets.

Malicious Coding Assignments Provide Initial Access

The campaign typically began through social media, online employment platforms, gig-work websites or freelance marketplaces.

After establishing contact with a prospective victim, the attackers allegedly instructed the individual to download and execute files presented as legitimate coding assignments or software fixes.

In some cases, malicious files were disguised as solutions to technical problems involving video-conferencing software.

Once executed, the malware provided the attackers with backdoor access to the victim’s computer. WaterPlum then used remote-access trojans and information-stealing malware to extract sensitive information, including cryptocurrency-related credentials.

The recruitment approach is particularly significant because developers may routinely be expected to download code, run development tools or troubleshoot unfamiliar software as part of legitimate hiring processes.

More Than 30,000 Devices Compromised

According to the joint advisory, WaterPlum compromised at least 30,000 devices in more than 100 countries.

Between December 2025 and July 2026, the campaign extracted funds or account credentials from more than 7,000 cryptocurrency wallets.

Authorities said the financial damage reached at least $10.7 million.

The impact can extend beyond cryptocurrency theft. Access to compromised systems can potentially provide attackers with information about the organizations employing targeted developers, creating an additional pathway into corporate environments.

Identity Theft Adds Another Layer of Risk

The campaign also involves the theft and misuse of personal identity information.

According to the advisory, stolen identity documents can allow North Korean IT workers to impersonate victims while securing employment and generating income. Sensitive personal or professional information can also potentially be used for extortion.

Authorities described a case involving a suspected North Korean IT worker who applied for an engineering position at a Japanese cryptocurrency exchange using a forged resume.

The exchange rejected the applicant after identifying inconsistencies during the interview, including difficulties explaining the technical skills listed on the resume in detail.

North Korean IT Worker Campaigns Remain a Concern

The WaterPlum campaign forms part of a broader pattern identified by international authorities involving North Korean IT workers seeking employment inside foreign organizations.

Japanese and US authorities assessed that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department.

The threat has also reached major cryptocurrency and blockchain companies. In July, Consensys disclosed that it had unknowingly engaged a North Korea-linked developer as a consultant. The company terminated the individual’s access after identifying the connection and said its investigation found no theft of assets or data, malicious code deployment or impact on user safety.

Cryptocurrency Theft Remains a Funding Channel

The campaign adds to a long-running pattern of North Korean-linked cryptocurrency theft.

US authorities have previously attributed major cryptocurrency thefts to North Korean actors, including the $1.5 billion theft from Bybit in February 2025. US authorities have also warned about North Korean IT workers operating covertly inside foreign companies for years.

The combination of cryptocurrency theft, identity fraud and employment infiltration creates a broader cybersecurity challenge for companies operating in digital assets and other technology-intensive industries.

Outlook

The WaterPlum campaign demonstrates how recruitment processes can become an attack vector for both individuals and organizations. For cryptocurrency and technology companies, the risk extends beyond losing funds from compromised wallets: a malicious developer or consultant can potentially provide attackers with access to corporate systems, credentials and sensitive information. The scale of the reported campaign, spanning more than 100 countries and thousands of cryptocurrency wallets, underscores the continuing importance of identity verification, technical screening and security controls during remote hiring and contractor onboarding.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | US Sanctions BitBank Over Bitcoin Payments Linked to Iran’s Hormuz Network

    Key Takeaways The U.S. Treasury sanctioned Iranian crypto exchange BitBank, alleging that it processed Bitcoin payments connected to vessels seeking passage through the...

    SKN | Zcash Miner Fortitude Names Former Hut 8 CEO Jaime Leverton Ahead of Nasdaq Listing

    Key Points Fortitude Mining has appointed former Hut 8 CEO Jaime Leverton as chief executive as the Zcash-focused miner prepares for a proposed...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY