North Korea’s WaterPlum Used Fake Job Interviews to Steal $10.7 Million in Crypto

Published:

North Korean cyber actors used fake job interviews to compromise thousands of devices and steal cryptocurrency in a campaign targeting technology professionals worldwide.

The WaterPlum group, also known as Contagious Interview, targeted software developers, web designers, blockchain specialists, and other IT professionals. Authorities said the campaign compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026.

The operation transferred about $10.71 million in cryptocurrency linked to more than 7,000 wallets. The campaign shows how North Korea continues to use social engineering alongside technical attacks to generate illicit revenue from the crypto industry.

How the fake interviews worked

WaterPlum operators approached job seekers through social media, employment websites, freelance platforms, and recruiting services. They often posed as recruiters for cryptocurrency, artificial intelligence, or NFT companies.

After establishing contact, the attackers invited candidates to technical interviews or coding tests. They then instructed applicants to download files or developer packages to complete an assignment or fix an alleged technical problem.

The files contained malware, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle variants.

Once installed, the malware could establish remote access and steal sensitive information. Targets included browser credentials, keystrokes, screenshots, clipboard data, identity documents, and cryptocurrency wallet information.

Why crypto professionals were targeted

The campaign focused heavily on people with access to digital assets and blockchain infrastructure. A compromised personal computer could provide direct access to wallet credentials.

Furthermore, attackers could use a victim’s credentials to pursue additional targets. If the victim later joined a technology company, the compromised device could potentially provide a pathway into corporate systems.

The campaign also overlaps with North Korea’s broader IT worker schemes. Those operations use stolen identities, intermediaries, remote access, and “laptop farms” to place North Korean workers into overseas technology jobs.

The growing risk for crypto firms

WaterPlum highlights a major weakness in crypto security: the hiring process itself can become an attack surface.

Job candidates should avoid running untrusted code during interviews. Companies can also verify applicants’ identities, employment histories, technical claims, contact details, and network locations before granting access to sensitive systems.

For crypto businesses, the incident underscores the need to treat recruitment as part of cybersecurity. A convincing interview invitation can be more than a career opportunity. It can also be the first step in a targeted attempt to reach valuable digital assets.

Adam L
Adam L
In the world of blockchain and cryptocurrencies, I have a great deal of passion and interest. My interest in blockchain and cryptocurrencies has led me to explore these technologies in greater depth, as I am interested in the potential implications they could have on the global economy.

Related News

Recent