WaterPlum Cybercriminals Deploy Fake Job Offers to Compromise 30,000 Devices, Siphon $10.7M in Digital Assets

WaterPlum Cybercriminals Deploy Fake Job Offers to Compromise 30,000 Devices, Siphon $10.7M in Digital Assets

The North Korean hacking collective WaterPlum leveraged fraudulent employment opportunities at cryptocurrency, artificial intelligence, and NFT firms to compromise a minimum of 30,000 devices spanning more than 100 nations while targeting software developers.

The North Korean cybercriminal organization known as WaterPlum successfully extracted a minimum of $10.7 million through an elaborate scheme where members masqueraded as talent acquisition professionals representing authentic cryptocurrency and artificial intelligence corporations, deploying malware against unwary individuals searching for employment opportunities.

This criminal organization, which also operates under the alias Contagious Interview, actively pursues software development professionals and information technology specialists across the globe, as detailed in a collaborative security bulletin issued by authorities from Japan, Germany, Australia and the US. Government agencies revealed that these fraudulent hiring personnel impersonated bona fide AI, cryptocurrency or non-fungible token (NFT) enterprises and additionally utilized professional recruiting platforms.

The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.

The security bulletin further establishes a connection between WaterPlum and North Korea's extensive operation of embedding IT professionals within international corporations, with Japanese and US intelligence agencies determining that WaterPlum operatives and certain North Korean IT personnel function under the authority of North Korea's Munitions Industry Department.

Based on information provided in the advisory, WaterPlum enticed individuals seeking employment opportunities via social networking websites, digital employment boards, gig economy platforms or independent contractor marketplaces. Throughout the hiring workflow, targeted individuals received instructions to download and run malicious software files masquerading as programming challenges or solutions for video-conferencing technical issues.

After the threat actors secured backdoor entry to a victim's computing device, they deployed remote-access trojans and information-stealing malware to extract confidential information and cryptocurrency holdings.

Compromised systems additionally generate pathways for WaterPlum threat actors to penetrate corporate networks that hire the unsuspecting software developers.

WaterPlum successfully compromised a minimum of 30,000 computing devices across more than 100 nations worldwide, with monetary assets or authentication credentials stolen from in excess of 7,000 cryptocurrency wallets during the period spanning December 2025 and July 2026.

Nevertheless, the consequences can reach far beyond pilfered cryptocurrency holdings. Compromised identification documentation enables North Korean IT professionals to assume victims' identities and generate revenue, and confidential data could be leveraged for blackmail purposes, it said.

The security bulletin outlined a specific incident in which an individual suspected of being a North Korean IT operative submitted an application for an engineering position at a Japanese cryptocurrency trading platform utilizing a fabricated professional resume. The exchange organization denied the candidate following the discovery of inconsistencies throughout the interviewing process, including a failure to articulate the competencies enumerated in his resume with adequate detail.

A more contemporary incident took place in July, when Cointelegraph published reports that Consensys had inadvertently contracted a North Korea-affiliated software developer to work as a consultant. The organization informed Cointelegraph it revoked their system access upon identifying the security threat, and a comprehensive investigation determined there was no misappropriation of assets or data, deployment of malicious programming code or adverse effects on user security.

The documented operation represents the most recent illustration of North Korea's relentless utilization of cryptocurrency theft as a mechanism to generate revenue notwithstanding years of advisories and legal enforcement. The FBI attributed responsibility to North Korea for the $1.5 billion Bybit security breach in February 2025, while US government officials have issued warnings regarding its clandestine IT workforce since at least 2018.

← Retour au blog