North Korea-Linked Hackers Steal $10.7M via Fake Crypto Recruiters
A North Korea-linked cyber group called WaterPlum has been accused of stealing at least $10.7 million by impersonating recruiters for legitimate cryptocurrency and AI companies.
The group, also known as 'Contagious Interview,' used a fake recruitment scheme to target software and IT professionals worldwide, using malware delivered during fake hiring workflows.
Victims were lured through recruiting channels and tricked into downloading and running malicious files disguised as coding tasks or fixes for video-conferencing problems.
Once attackers gained access, they used remote-access tools and infostealing malware to extract both data and cryptocurrency.
The campaign infected at least 30,000 devices in over 100 countries, with funds or credentials extracted from over 7,000 cryptocurrency wallets between December 2025 and July 2026.