← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 19, 2026 · 08:48via CyberPress

North Korean WaterPlum Hackers Infect 30,000 Devices via Fake Job Interviews to Steal Crypto

Brief

North Korean threat actors, tracked as WaterPlum (also known as Contagious Interview), have compromised at least 30,000 devices across over 100 countries by posing as recruiters and potential employers.

This campaign primarily targets developers, web freelancers, and cryptocurrency professionals, resulting in the theft of funds or account credentials from more than 7,000 cryptocurrency wallets.

A joint advisory from Japanese, U. S. , Australian, and German authorities indicates that this activity occurred from approximately December 2025 to July 2026.

Investigators estimate that the operation generated at least JPY 1. 7 billion, roughly equivalent to $10. 71 million, in stolen cryptocurrency for the Democratic People’s Republic of Korea (DPRK).

North Korean WaterPlum Hackers

WaterPlum utilizes job-search and freelance platforms as an initial access vector.

Read more on CyberPress→