North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate crypto and AI companies. The group targeted software developers and IT professionals worldwide, infecting more than 30,000 devices in over 100 countries with malware to steal cryptocurrency and sensitive data. This joint advisory was issued by authorities from Japan, Germany, Australia, and the US.
Why it matters
The advisory highlights the sophisticated tactics used by North Korean hackers to infiltrate global IT ecosystems by exploiting job seekers. This campaign not only results in significant financial theft but also poses security risks to organizations hiring affected developers, as stolen identities can be used for further infiltration and extortion. The source does not elaborate further on broader market or policy impacts.
Key context
WaterPlum’s activities are linked to North Korea’s Munitions Industry Department, which reportedly employs IT workers in foreign companies as part of a broader espionage and fundraising campaign. Similar threats have been reported since at least 2018, and North Korea’s use of cryptocurrency theft to generate funds has been repeatedly documented, including a $1.5 billion theft from Bybit in 2025. Recruiting platforms and social media are used for luring victims with fake coding tasks containing malware.
Key numbers and entities
WaterPlum (Contagious Interview) hacked over 30,000 devices and extracted funds or credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The theft amounted to at least $10.7 million. Key organizations involved include Japanese, German, Australian, and US authorities, as well as companies like Consensys and a Japanese crypto exchange mentioned in related incidents.
What remains unclear
The source does not specify detailed technical information on the malware used or the full scope of organizations impacted beyond the general figures. It also does not clarify the long-term consequences for victims or the effectiveness of countermeasures. The source does not provide detailed information on how WaterPlum coordinates with North Korean IT workers or the specifics of the Munitions Industry Department’s involvement.