Key Takeaways
- Cybercriminals with ties to North Korea successfully compromised over 30,000 computing devices across more than 100 nations through fraudulent employment opportunities.
- Officials confirmed that attackers breached more than 7,000 digital currency wallets.
- A minimum of $10.7 million in cryptocurrency was siphoned off and routed to North Korea.
- The cybercrime operation, identified as WaterPlum, focused on software engineers and technology professionals by advertising false positions at cryptocurrency, artificial intelligence, and non-fungible token firms.
- Targets were frequently instructed to execute malicious software masked as technical assessments or solutions for video conferencing issues.
A cybercriminal organization with connections to North Korea deployed fraudulent hiring campaigns to compromise more than 30,000 computing systems and extract a minimum of $10.7 million in digital assets, based on a coordinated international security alert.
The cybercrime syndicate, identified as WaterPlum and Contagious Interview, focused their efforts on software engineers and information technology specialists spanning over 100 nations.
Law enforcement agencies from the United States, Japan, Australia, and Germany revealed that the attackers impersonated hiring managers representing seemingly authentic cryptocurrency, blockchain, artificial intelligence, and NFT enterprises.
According to reports, more than 7,000 digital currency wallets were successfully breached during the period spanning December 2025 through July 2026.
Fraudulent Cryptocurrency Employment Opportunities Deploy Malicious Software
WaterPlum contacted potential victims via social networking platforms, employment websites, independent contractor marketplaces, and professional recruiting services.
The threat actors presented compelling career prospects before transitioning candidates into a fabricated technical evaluation process.
Targets were subsequently instructed to execute files or run programming scripts as components of purported coding challenges.
In alternative scenarios, job seekers were informed they must install applications to resolve alleged difficulties with video communication platforms.
These files actually contained malicious software engineered to provide attackers with unauthorized system access.
Officials identified multiple malware variants deployed throughout the operation, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
After successful installation, the malicious programs could harvest browser authentication credentials, clipboard contents, screen captures, keyboard input, and stored documents.
Cryptocurrency private keys and wallet recovery phrases were specifically prioritized by attackers.
Cybercriminals Extract $10.7 Million in Digital Currency
Officials confirmed that WaterPlum successfully exfiltrated assets or authentication credentials from over 7,000 cryptocurrency storage wallets.
A confirmed minimum of $10.71 million in stolen digital currency was channeled to North Korea, the advisory stated.
The intrusions may also generate broader security vulnerabilities for organizations that employ victimized developers.
Once threat actors establish access to an employee’s workstation, compromised credentials can potentially be leveraged to infiltrate corporate networks, consumer information, or proprietary business intelligence.
Personal identification documentation represented another objective.
Authorities indicated that stolen passport scans and identity documents could be exploited by North Korean IT personnel to assume victims’ identities when seeking employment opportunities abroad.
Compromised information could additionally be weaponized for blackmail purposes.
Investigators revealed that certain WaterPlum operatives utilized artificial intelligence-powered face-swapping tools during virtual interviews before disabling their cameras and citing technical difficulties.
North Korean IT Personnel Operation Persists
The security advisory connected WaterPlum to North Korea’s broader initiative to embed IT professionals within international corporations.
American and Japanese intelligence agencies assess that WaterPlum actors and certain North Korean IT contractors function under an organizational unit affiliated with the nation’s military-industrial complex.
One suspected North Korean IT operative recently submitted an application for a software engineering position at a Japanese cryptocurrency trading platform using falsified credentials.
The candidate was declined after interviewers detected inconsistencies between the individual’s documented background and their capacity to articulate the specified technical competencies.
ConsenSys additionally revealed in July that it had inadvertently contracted a North Korea-affiliated developer as an external consultant.
The organization revoked the individual’s system access upon discovering the affiliation and stated that internal investigation determined no asset misappropriation, data exfiltration, malicious code insertion, or compromise of user security.
Authorities recommend that job applicants refuse to execute code or download materials from unverified recruiters and immediately isolate potentially compromised devices from network connectivity.


