North Korean Hackers Drain $10M from 7,000 Crypto Wallets with Fake Job Interviews
A sophisticated North Korean hacking campaign has drained over $10 million from more than 7,000 cryptocurrency wallets. The group, known as WaterPlum or Contagious Interview, targets web designers, engineers, and crypto specialists with fake job interviews.
The hackers use AI face-swapping software to impersonate recruiters and convince victims to download malware-laced files. These files contain five different malware families, including BeaverTail, InvisibleFerret, and StoatWaffle, which hide in blockchain-themed repositories.
The operation is linked to North Korea's 313 General Bureau of the Munitions Industry Department, with some of its remote IT workers reporting directly to this organization. The hackers have infected at least 30,000 devices across over 100 countries between December 2025 and July 2026.