North Korean hackers stole $10.7M in crypto via fake job lures, say US, allies

WaterPlum campaign infected 30,000 devices across 100+ countries, targeting developers with phony crypto, AI, and NFT roles

By LineZotpaper
Published
Read Time2 min
A North Korean cyber group dubbed WaterPlum—also known as Contagious Interview—has stolen at least $10.7 million in cryptocurrency by posing as recruiters for legitimate crypto, AI, and NFT firms, infecting at least 30,000 devices across more than 100 countries, according to a joint advisory from Japan, Germany, Australia, and the US.

The WaterPlum threat actor, also tracked as Contagious Interview, has been running a large-scale social engineering campaign that impersonates legitimate AI, cryptocurrency, and NFT companies to lure software developers and IT professionals into downloading malware, the advisory states.

According to the joint cybersecurity advisory published by authorities in Japan, Germany, Australia, and the US, the group has stolen at least $10.7 million in cryptocurrency and infected no fewer than 30,000 devices globally. The campaign's precise targeting of developers and IT workers—often through fake job offers—has made it a significant concern for the tech and crypto sectors.

The advisory highlights the international scope of the operation, which spans more than 100 countries. The attackers posed as recruiters for crypto, AI, and non-fungible token (NFT) companies, a tactic designed to exploit the high volume of remote job applications in these industries. The stolen funds and infected machines are consistent with known North Korean cyber activity, which often funnels illicit proceeds toward state priorities.

While the advisory does not name specific victim companies, it warns that any software developer or IT professional applying for roles in these sectors could be targeted. The campaign's reliance on fake recruitment lures makes it particularly insidious, as it exploits the trust job seekers place in hiring processes.

The joint advisory from the four nations underscores the transnational nature of the threat and the need for coordinated defense. It recommends that employers and job seekers alike verify the legitimacy of recruiters and be cautious of unsolicited job offers, especially those involving cryptocurrency or blockchain-related roles.

§

Analysis

Why this matters

  • The campaign directly threatens the livelihood of software developers and IT professionals worldwide, as fake job offers are being weaponized to deploy malware and steal cryptocurrency.
  • The scale—30,000 infected devices and $10.7 million stolen—demonstrates the persistent and evolving nature of North Korean state-sponsored cyber operations targeting the tech workforce.
  • The joint advisory from four nations signals a coordinated international response, which could lead to increased scrutiny of recruitment practices in the crypto and AI sectors and may prompt companies to harden their hiring pipelines.

Background

North Korean cyber actors have a long history of targeting the cryptocurrency sector, often using social engineering and supply-chain attacks to steal digital assets. WaterPlum, also referred to as Contagious Interview, is part of a pattern of North Korean IT worker and hacking groups that fund state activities through cybercrime. The group's method of posing as recruiters for legitimate companies is a well-documented tactic known as 'luring' or 'social engineering,' where attackers exploit human trust rather than technical vulnerabilities. This campaign reflects a broader trend of state-sponsored actors increasingly targeting developers and IT staff, who often have access to valuable corporate networks and digital assets.

Key perspectives

  • Law enforcement and cybersecurity agencies (US, Japan, Germany, Australia): They emphasize the global reach of the operation and urge vigilance, providing technical indicators and best practices to mitigate the threat.
  • Crypto and AI companies (as potential employers): These firms face reputational and operational risks if their names are impersonated; they may need to strengthen their recruitment verification processes to protect job seekers and their own brand.
  • Job seekers and IT professionals: They are the primary targets, and their perspective highlights the need for individual caution, such as verifying recruiter identities through official channels and avoiding unsolicited links or attachments.
  • Critics and skeptics: Some may question the completeness of the advisory, as it lacks specific indicators of compromise or detailed attribution methods, making it difficult for independent verification of the campaign's full scope.

What to watch

  • Further disclosures from the joint advisory or cybersecurity firms that may reveal the specific malware families or command-and-control infrastructure used by WaterPlum.
  • Indicators that the campaign is expanding beyond software developers to other roles, such as human resources or operations staff at crypto and AI companies.
  • Responses from major job platforms (e.g., LinkedIn, Indeed) or crypto firms to detect and remove fake recruiter profiles, which could reduce the effectiveness of similar attacks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.