
WaterPlum fake recruiters hit 30,000 devices and 7,000 wallets for $10.7M+
A multi-country advisory ties the North Korea-linked campaign to malware delivered through hiring workflows.
A North Korea-linked cyber group known as WaterPlum, or “Contagious Interview,” stole at least $10.7 million by posing as recruiters and pushing malware to crypto and AI job seekers. A multi-country advisory said the campaign infected at least 30,000 devices across 100+ countries and pulled funds or credentials from 7,000+ crypto wallets from December 2025 through July 2026.
WaterPlum’s fake-recruiter campaign: 30,000 devices, 7,000 wallets, $10.7M+ stolen
Authorities tied a sustained fake-recruiter operation to WaterPlum, a North Korea-linked cluster also tracked as “Contagious Interview.” The core number is $10.7 million. That is the minimum confirmed theft attributed to the campaign, with the advisory framing losses as “at least,” leaving room for uncounted victims.
The scale is what changes the read. Authorities said the operation infected at least 30,000 devices across more than 100 countries. That is not a single-region scam wave. It is a broad distribution model that fits global hiring markets, where crypto teams routinely source contractors and engineers across jurisdictions.
The wallet impact is not a rounding error either. Authorities said funds or account credentials were extracted from over 7,000 cryptocurrency wallets between December 2025 and July 2026. Eight months of consistent extraction points to an operational pipeline, not a one-off lure that happened to work.
The targeting profile is explicit and crypto-native. “The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” the advisory said. The counterparty here is the hiring funnel itself, where trust is temporarily extended and verification is weakest.
The advisory also linked WaterPlum to North Korea’s broader effort to place IT workers inside foreign companies. Japanese and US authorities assessed that WaterPlum actors and some North Korean IT workers operate under North Korea’s Munitions Industry Department. The excerpted advisory does not name the specific issuing agencies or provide a direct link to the full text, which limits independent review of indicators and methodology.
Recruiting workflows as the infection vector: ‘coding tests’ and video-call ‘fixes’ delivering RATs and infostealers
The delivery mechanism is mundane by design. Authorities said WaterPlum lured job seekers through social media platforms, online job platforms, gig work platforms, and freelance marketplaces. The hook is a normal next step in hiring, then the pivot is execution.
Victims were instructed to download and run files presented as coding assignments or as fixes for video-conferencing errors during interviews. That execution step is the breach point. It bypasses most “onchain hygiene” because the compromise happens on the endpoint before a transaction is ever signed.
Once the actors obtained backdoor access, authorities said they used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. A RAT is persistent remote control of the machine. An infostealer is built to pull stored credentials, cookies, and wallet-related data off the device. Backdoor access means the attacker can return without repeating the lure.
The second-order risk is downstream. The advisory warned that successful infections create opportunities to infiltrate organizations that employ the compromised developers. That is the supply-chain angle. A single infected contractor can become a path to internal repos, deployment credentials, or operational keys, depending on how a team segments access.
The advisory also described non-crypto monetization paths. Stolen identity documents can be used to impersonate victims and earn income, and sensitive information can be used for extortion. One case example described a suspected North Korean IT worker applying for an engineering role at a Japanese crypto exchange using a forged resume, then failing interview scrutiny when they could not explain listed skills in detail.
A separate July case cited in the excerpt said Consensys unknowingly engaged a North Korea-linked developer as a consultant, then terminated access after discovering the threat. The company said an investigation found no theft of assets or data, no malicious code deployment, and no impact on user safety. That is the clean outcome. It is also the point: detection often happens after access is granted.
Why this matters now for crypto teams and traders: compromised dev endpoints become downstream breach risk
The threshold that matters is not $10.7 million. It is 30,000 infected devices across 100+ countries, because that distribution implies the campaign is built to keep recycling through global hiring flows rather than burning out on a single platform.
The real test is whether follow-on government or CERT updates publish indicators of compromise like hashes, domains, and lure infrastructure, and whether major crypto firms start disclosing recruiter-lure incidents beyond the advisory’s July 2026 window. If the ecosystem can map which chains, wallet types, and custody setups sit inside the 7,000+ wallet figure, this shifts from a generic cyber headline into a concrete exposure model for teams and traders who rely on developer endpoints.