Fake North Korean Recruiters Infect 30,000 Devices, Stealing $10.7M in Crypto

Date:

North Korean cyber group WaterPlum posed as recruiters for crypto, AI and NFT companies, using fake job offers to target developers. The campaign has infected at least 30,000 devices across more than 100 countries.

North Korean hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate crypto and AI firms, targeting unsuspecting job seekers with malware disguised through fake employment opportunities.

The group, also known as Contagious Interview, targets software developers and IT professionals worldwide, according to a joint advisory issued by authorities in Japan, Germany, Australia and the US. The attackers also posed as recruiters for non-fungible token (NFT) companies and used legitimate recruitment platforms to reach potential victims.

“The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,”

they added.

The advisory also connects WaterPlum to North Korea’s wider effort to place IT workers at foreign companies. Japanese and US authorities assess that WaterPlum operatives and some North Korean IT workers work under the country’s Munitions Industry Department.

According to the advisory, WaterPlum approached job seekers through social media, online job boards, gig-work sites and freelance marketplaces. During recruitment, victims were asked to download and run malicious files presented as coding tasks or supposed fixes for video-conferencing problems.

After gaining backdoor access to a victim’s computer, the cyber actors deployed remote-access trojans and information-stealing malware to extract sensitive data and cryptocurrency.

Successful infections can also give WaterPlum operators a pathway into organizations where the targeted developers work, potentially expanding the campaign beyond individual victims.

WaterPlum compromised at least 30,000 devices across more than 100 countries, extracting funds or account credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.

Forged Resume Exposes Suspected North Korean IT Worker

However, the fallout can reach beyond stolen cryptocurrency. According to the advisory, North Korean IT workers can use stolen identity documents to impersonate victims and generate income, while sensitive data could also be used to pressure or extort them.

The advisory detailed a case involving a suspected North Korean IT worker who applied for an engineering position at a Japanese crypto exchange with a forged resume. The exchange rejected the candidate after interview discrepancies emerged, including his inability to explain the skills listed on his resume in detail.

A more recent case emerged in July, when reported that Consensys had unknowingly hired a North Korea-linked developer as a consultant. The company told that it cut off the developer’s access after identifying the threat. An internal investigation found no evidence of asset or data theft, malicious code deployment, or any impact on user safety.

The reported campaign adds to a long record of North Korea using cryptocurrency theft to generate revenue despite years of warnings and enforcement efforts. The FBI attributed the $1.5 billion Bybit theft in February 2025 to North Korea, while US authorities have warned about its covert IT worker operations since at least 2018.

Marton K.
Marton K.https://thecoingraph.com
Marton is seasoned crypto and finance journalist with over four years of experience. He has contributed to several high-profile outlets.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

spot_imgspot_img

Popular

More like this
Related

Lemon Exits Brazil Over Rising Crypto Licensing Costs

Lemon will shut down its Brazilian operations and close...

Vitalik Buterin Says Local AI Can Boost Privacy While Maintaining Speed

Ethereum co-founder Vitalik Buterin says laptop-based AI is moving...

XRP ETFs Face a Speed Bump as Big Investors Hold Onto Their Tokens

A monthly influx of $192 million is being rigorously...

Wall Street Gains Greater Web3 Security Oversight as S&P Global Acquires OpenZeppelin

The security firm says its team and technology will...