North Korea's WaterPlum Hackers Steal $10.7M from 7,000 Crypto Wallets via Fake Job Interviews
A joint law enforcement advisory published in September 2026 details a new North Korean cryptocurrency theft operation called WaterPlum, which infected at least 30,000 devices across more than 100 countries and pulled funds or account credentials out of over 7,000 cryptocurrency wallets. The campaign, also tracked as Contagious Interview, targeted software developers, web designers, and people working in cryptocurrency, blockchain, or Web3 roles with fake job interview pitches.
The malware was delivered through a 'technical assessment' that victims were asked to complete to move forward in the hiring process, which installed malicious code on their devices capable of harvesting credentials, browser session data, and wallet access. The attackers then transferred 1.7 billion Japanese yen ($10.71 million) of cryptocurrency assets to North Korea between December 2025 and July 2026.
The advisory was issued by a coordinated effort involving Japan's National Police Agency, the FBI, the U.S. Department of Defense Cyber Crime Center, Australia's Cyber Security Centre, and German authorities.