In a sophisticated cyber attack, the North Korean-affiliated group known as WaterPlum has manipulated job interviews to facilitate cryptocurrency theft. By masquerading as legitimate recruiters, the hackers deceived software developers into executing malicious files, turning routine interviews into opportunities for cybercrime.
Global Reach of the WaterPlum Campaign
Between December 2025 and July 2026, the campaign, dubbed ‘Contagious Interview,’ impacted over 30,000 computers across more than 100 nations. The attackers successfully infiltrated over 7,000 cryptocurrency wallets, redirecting at least $10.7 million worth of cryptocurrency to North Korea.
The Internet Crime Complaint Center (IC3) has highlighted this as part of a broader pattern of North Korean cyber activity targeting IT workers. Their report, shared with Cyber Security News (CSN), emphasizes the potential exploitation of standard recruitment practices to introduce malware into systems containing sensitive data.
Methods and Tools Used by Hackers
WaterPlum leveraged social media, job websites, and freelance platforms to approach targets, posing as potential employers. Candidates were instructed to complete coding tasks or fix alleged software issues, which in reality involved downloading and running harmful software.
The malware included tools like BeaverTail, InvisibleFerret, and StoatWaffle, designed to establish remote access and exfiltrate data. Notably, StoatWaffle could be concealed within blockchain projects, activating malicious code when unsuspecting developers opened these projects in trusted environments.
Wider Implications and Safety Measures
Beyond individual losses, stolen credentials can compromise employers and clients, leading to intellectual property theft and network breaches. Identity theft facilitated by images of victims can further aid North Korean IT workers in securing fraudulent contracts and income.
Authorities have linked certain operations to North Korean IT workers employing ‘laptop farms’ – setups of remotely controlled computers – to obscure the true origins of their activities. Japan recently dismantled such an operation tied to these cybercriminals.
Both employers and job seekers are urged to exercise caution. Employers should verify applicant details thoroughly, while candidates are advised against executing unverified code on devices containing sensitive data. Suspected infections should be addressed by disconnecting the device from the internet and securing wallet data immediately.
This incident underscores a recurring threat where enticing job offers mask dangerous downloads. Comparisons can be drawn to similar campaigns like ‘Contagious Interview,’ emphasizing the need for vigilance in digital interactions.
