North Korean Hackers Use Fake Jobs to Infiltrate 30,000 Devices Worldwide
A joint advisory from authorities in Japan, the U.S., Australia, and Germany has revealed that North Korean-linked cyber actor WaterPlum infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026. The campaign used fake job offers tied to AI, cryptocurrency, and NFT companies to steal funds or credentials from over 7,000 crypto wallets.
The actors posed as legitimate employers on social media, recruitment sites, and freelance platforms, luring victims into downloading malicious files presented as coding tests, interview assignments, or development projects. The primary targets were web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web3.
Authorities said the operation transferred at least 1.7 billion Japanese yen (approximately $10.71 million) in crypto assets on behalf of North Korea. The WaterPlum campaign has been linked to the activity commonly referred to as 'Contagious Interview,' a social-engineering pattern in which attackers impersonate recruiters and push malware through supposed hiring processes.