North Korea-Linked Cyber Group Steals $10.7 Million Through Fake Recruitment Scheme
A North Korea-linked cyber group called WaterPlum, also known as Contagious Interview, has been accused of stealing at least $10.7 million through a fake recruitment scheme targeting software and IT professionals worldwide.
The campaign uses social engineering with direct technical compromise: victims are lured in through recruiting channels and tricked into downloading and running malicious files disguised as coding tasks or 'fixes' for video-conferencing problems.
Once attackers gain access, they use remote access tools and infostealing malware to extract both data and cryptocurrency. The group has compromised at least 30,000 devices in over 100 countries, with over 7,000 cryptocurrency wallets affected between December 2025 and July 2026.