U.S. and allied agencies said WaterPlum, also called Contagious Interview, is running a long campaign through fake employers, recruiter outreach, and contractor work, and tied the activity to North Korea’s 313 General Bureau. The coordinated alert puts the operation at more than 30,000 infected devices across 100 countries and more than $10 million taken from over 7,000 crypto wallets.
The lure is ordinary hiring work: applicants are asked to open job files, coding tests, or other interview materials, and that step delivers malware that steals wallet data and can keep access on the machine. The same pattern also overlaps with North Korean IT-worker placements, where stolen identities and access help the group move from personal devices into corporate web systems.
For technology companies that hire through recruiters, tests, or freelance channels, the trust boundary is not just the inbox. A compromised candidate device can carry stolen credentials and persistence into a later employer environment, so the reporting leaves the exposure sitting in the recruiting and contractor pipeline as much as on the endpoint.
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
International security agencies warned that North Korean hacker group WaterPlum is posing as prospective employers to target job seekers and steal millions in cryptocurrency.