
A North Korean-linked hacking group stole at least $10.71 million in cryptocurrency after compromising more than 30,000 devices and targeting thousands of crypto wallets through fake job opportunities and malicious software, according to a joint international cybersecurity advisory.
The group, known as WaterPlum and also commonly referred to as "Contagious Interview," targeted software developers, web designers and other IT professionals in more than 100 countries, including the United States and Japan, according to Australia's Cyber Security Centre.
Authorities said WaterPlum compromised at least 30,000 devices between December 2025 and July 2026 and exfiltrated funds or account credentials from more than 7,000 cryptocurrency wallets. At least 1.7 billion Japanese yen, or about $10.71 million, in cryptocurrency was transferred on behalf of North Korea.
The advisory was issued by agencies including Japan's National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, Germany's Federal Intelligence Service and its domestic intelligence agency.
WaterPlum frequently posed as a legitimate employer advertising jobs to software developers and other technology workers. The group used social media, job platforms, freelance marketplaces and recruiting services to approach potential victims.
During technical interviews or coding assignments, victims were instructed to download files or run code from online developer platforms and repositories. Those files could contain malware designed to steal credentials, cryptocurrency wallet information and other sensitive data.
Authorities identified several malware families used in the campaign, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Once installed, the malware could give attackers remote access to a device and allow them to collect information or maintain access to compromised networks.
The group also used AI face-swapping software during some online interviews, according to the advisory. In observed cases, the actors initially appeared on camera before turning off their video and asking the other participant to do the same, citing network problems.
Authorities also linked WaterPlum activity to North Korean IT workers who seek legitimate remote jobs while concealing their real identities and locations.
Investigators in Japan dismantled a so-called laptop farm, where computers were set up in one location but remotely controlled by North Korean workers elsewhere. The advisory said those workers were often located in North Korea, China or Russia, with smaller numbers operating from Africa and Southeast Asia.
North Korean IT workers have also used stolen or supplied identity documents, third-party bank accounts and remote-access systems to obtain employment and receive payments.
The advisory said investigators found evidence that North Korean IT workers transferred hundreds of millions of yen abroad, including cryptocurrency assets. It also warned that stolen IDs and credentials could later be used to impersonate victims, steal company data or support extortion attempts.
The National Police Agency of Japan and the FBI assess that both WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is subordinate to the Central Committee of North Korea's Workers' Party.
University of Melbourne cybersecurity and AI specialist Andrew Cullen told ABC News that fake North Korean workers had been reported for several years, although the activity had accelerated.
The latest warning follows a series of cryptocurrency thefts attributed to North Korean state-backed actors.
In February 2025, the FBI said North Korea was responsible for the theft of approximately $1.5 billion in virtual assets from cryptocurrency exchange Bybit. The agency identified that campaign as "TraderTraitor" and said stolen assets had been converted into Bitcoin and other virtual currencies and moved across thousands of blockchain addresses.

