North Korea's WaterPlum Hacking Group Steals $10.7M from Job Seekers
A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by posing as recruiters for legitimate crypto and AI companies, targeting software developers and IT professionals worldwide. The group, also referred to as Contagious Interview, infected at least 30,000 devices in over 100 countries between December 2025 and July 2026.
The hackers used social media platforms, online job platforms, gig work platforms, or freelance marketplaces to lure job seekers into downloading malicious files disguised as coding assignments or fixes for video-conferencing errors. Once they obtained backdoor access to a victim's computer, they used remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency.
The group also created opportunities for WaterPlum actors to infiltrate organizations that employ the unsuspecting developers. According to authorities, stolen identity documents allow North Korean IT workers to impersonate victims and earn income, while sensitive information could be used for extortion.