North Korean Hacking Group Steals $10.7 Million in Crypto by Posing as Fake Recruiters
A North Korean hacking group called WaterPlum has stolen $10.7 million in cryptocurrency by posing as fake recruiters for legitimate crypto and AI companies. The group, also known as Contagious Interview, targets software developers and IT professionals worldwide.
According to a joint advisory from Japan, Germany, Australia, and the US, WaterPlum infected at least 30,000 devices in over 100 countries between December 2025 and July 2026. The group used social media platforms, online job platforms, gig work platforms, or freelance marketplaces to lure victims into downloading malicious files disguised as coding assignments.
The malware allowed the hackers to steal sensitive data and cryptocurrency from over 7,000 wallets. Additionally, stolen identity documents were used by North Korean IT workers to impersonate victims and earn income, while sensitive information could be used for extortion.