The WaterPlum threat actor, also tracked as Contagious Interview, has been running a large-scale social engineering campaign that impersonates legitimate AI, cryptocurrency, and NFT companies to lure software developers and IT professionals into downloading malware, the advisory states.
According to the joint cybersecurity advisory published by authorities in Japan, Germany, Australia, and the US, the group has stolen at least $10.7 million in cryptocurrency and infected no fewer than 30,000 devices globally. The campaign's precise targeting of developers and IT workers—often through fake job offers—has made it a significant concern for the tech and crypto sectors.
The advisory highlights the international scope of the operation, which spans more than 100 countries. The attackers posed as recruiters for crypto, AI, and non-fungible token (NFT) companies, a tactic designed to exploit the high volume of remote job applications in these industries. The stolen funds and infected machines are consistent with known North Korean cyber activity, which often funnels illicit proceeds toward state priorities.
While the advisory does not name specific victim companies, it warns that any software developer or IT professional applying for roles in these sectors could be targeted. The campaign's reliance on fake recruitment lures makes it particularly insidious, as it exploits the trust job seekers place in hiring processes.
The joint advisory from the four nations underscores the transnational nature of the threat and the need for coordinated defense. It recommends that employers and job seekers alike verify the legitimacy of recruiters and be cautious of unsolicited job offers, especially those involving cryptocurrency or blockchain-related roles.