Threats · 2 days ago
U.S. and allied agencies said WaterPlum, also called Contagious Interview, is running a long campaign through fake employers, recruiter outreach, and contractor work, and tied the activity to North Korea’s 313 General Bureau. The coordinated alert puts the operation at more than 30,000 infected devices across 100 countries and more than $10 million taken from over 7,000 crypto wallets.
The lure is ordinary hiring work: applicants are asked to open job files, coding tests, or other interview materials, and that step delivers malware that steals wallet data and can keep access on the machine. The same pattern also overlaps with North Korean IT-worker placements, where stolen identities and access help the group move from personal devices into corporate web systems.
For technology companies that hire through recruiters, tests, or freelance channels, the trust boundary is not just the inbox. A compromised candidate device can carry stolen credentials and persistence into a later employer environment, so the reporting leaves the exposure sitting in the recruiting and contractor pipeline as much as on the endpoint.
4 sources covering this story
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
North Korea's fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
International security agencies warned that North Korean hacker group WaterPlum is posing as prospective employers to target job seekers and steal millions in cryptocurrency.
The Record from Recorded Future
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
Part of the PlainSec briefing for 2026-09-21