Skip to main content

North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M



North Korea-linked cyber group WaterPlum, also known as “Contagious Interview,” is accused of stealing at least $10.7 million by impersonating recruiters for legitimate cryptocurrency and AI companies. According to a joint advisory cited by authorities in Japan, Germany, Australia and the United States, the operation targets software and IT professionals worldwide, using malware delivered during fake hiring workflows.



The campaign blends social engineering with direct technical compromise: victims are lured through recruiting channels and then tricked into downloading and running malicious files disguised as coding tasks or “fixes” for video-conferencing problems. Once attackers gain access, they use remote access tools and infostealing malware to extract both data and cryptocurrency.



Key takeaways



  • At least $10.7 million stolen, according to the joint advisory, via a fake recruitment scheme tied to WaterPlum.

  • More than 30,000 device infections across over 100 countries were attributed to the group.

  • 7,000+ cryptocurrency wallets affected between December 2025 and July 2026, with funds or credentials reportedly extracted.

  • The lure is professional hiring: attackers impersonate AI, crypto and Web3 companies and sometimes leverage recruiting services.

  • Secondary harm extends beyond theft, including identity document misuse and opportunities for impersonation, extortion, or further infiltration.



Recruitment scams as an entry point to crypto targets


In the advisory referenced by participating governments, WaterPlum is described as focusing on individuals such as web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The group reportedly uses social media, mainstream job platforms, gig work marketplaces, and freelance sites to reach candidates—then attempts to move victims into a “recruiting process” that culminates in malicious execution.



Authorities say the attackers impersonate legitimate companies, including those described as operating in the AI, cryptocurrency and NFT space. In some cases, the advisory also notes the use of recruiting services as part of the deception, potentially making the campaign look more credible to applicants who may be unfamiliar with threat patterns.



Malware delivery disguised as work tasks


The advisory describes a workflow designed to lower victims’ suspicion. During recruitment, job seekers are reportedly instructed to download and execute malicious files that are presented as coding assignments or as troubleshooting materials, including alleged fixes for video-conferencing errors.



This matters for organizations and candidates because it turns a common administrative step—reviewing a “take-home” task or installing something to support an interview or call—into a high-risk trigger. For employers in the crypto and AI sector, it also increases the chance that a compromised machine becomes the starting point for a deeper breach, not just an isolated incident.



Backdoor access, data theft, and wallet compromise


Once infections succeed, WaterPlum is said to establish backdoor access to a victim’s device. The advisory attributes subsequent activity to the use of remote-access trojans alongside infostealing malware to exfiltrate sensitive information and cryptocurrency-related assets.



In terms of scale, the advisory claims that WaterPlum infected at least 30,000 devices in more than 100 countries. It also alleges that between December 2025 and July 2026, the group extracted funds or account credentials from over 7,000 cryptocurrency wallets.



While these figures indicate substantial operational reach, the advisory also emphasizes that the campaign’s purpose is broader than direct theft. Stolen identity documents and other personal data can enable attackers to impersonate victims, pursue employment or access opportunities, and potentially support extortion efforts.



Linked to North Korea’s use of IT access inside foreign firms


The advisory links WaterPlum to North Korea’s wider pattern of placing IT workers into foreign organizations. Japanese and US authorities assess that WaterPlum actors—and at least some North Korean IT workers—operate under North Korea’s Munitions Industry Department.



The report also includes an example in which a suspected North Korean IT worker applied to a role at a Japanese crypto exchange using a forged resume. Authorities said the exchange rejected the applicant after inconsistencies surfaced during interviews, including an inability to discuss skills listed on the resume in detail.



More recently, Cointelegraph previously reported a case involving Consensys, which had unknowingly engaged a North Korea-linked developer as a consultant. Cointelegraph reported that the company terminated the individual’s access after identifying the threat. In that case, an investigation reportedly found no evidence of asset or data theft, malicious code deployment, or impact on user safety.



Taken together, these examples reinforce a recurring asymmetry: even when companies stop short of a full compromise, the recruitment stage itself can still create risk—through compromised endpoints, identity fraud, and attempts to gain legitimate access to organizations that handle crypto-adjacent workflows.



Why the story matters for crypto teams now


WaterPlum’s alleged tactics arrive amid continuing concern from US authorities about North Korea’s persistent efforts to use cyber operations and cryptocurrency theft to fund activity. The advisory references years of warnings and enforcement, and earlier coverage highlighted claims that the FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025. It also points to US Treasury statements warning about undercover IT workers dating back to at least 2018.



For crypto employers and candidates, the practical takeaway is that security scrutiny needs to extend beyond “obvious” phishing. Recruitment processes—especially those involving coding tasks, file downloads, or remote collaboration—should be treated as an attack surface. Conducting verification steps, using safe sandboxing for any executables, and ensuring that sensitive systems are protected against endpoint compromise can reduce the chance that a job offer becomes a foothold.



Readers should watch next for whether regulators and major crypto organizations publish updated hiring security guidance in response to the advisory’s details, and whether more victims or additional campaigns linked to WaterPlum are identified—particularly around the reported wallet credential extractions and the use of stolen identities for follow-on access.



https://www.cryptobreaking.com/north-korean-fake-recruiters-compromise/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=North%20Korean%20Fake%20Recruiters%20Compromise%2030K%20Devices,%20Steal%20$10.7M%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...