I uncovered joint security warnings issued by authorities in Japan, Germany, Australia, and the United States about a large-scale campaign carried out by a hacking group linked to North Korea, known as WaterPlum. The campaign targeted developers and technical specialists through fake job offers at companies operating in the fields of cryptocurrency, artificial intelligence, and NFTs.
According to the alert, the group succeeded in taking at least $10.7 million by impersonating legitimate hiring organizations, and then pushing victims to download malicious files that appeared to be part of the hiring process. The group is also known as Contagious Interview.
How was the campaign carried out?
WaterPlum relied on multiple channels to reach victims, including social media platforms, job boards, freelancing platforms, and independent services marketplaces. During contact with candidates, the attackers asked them to run malicious files that were disguised as:
• Programming tasks related to the interview
• Fixes for issues in video calls
• Support files that appear to be a natural part of the hiring process
Once the attackers gained backdoor access to the victim’s device, they used remote access software and information-stealing malware to extract sensitive data and digital assets. Moreover, the success of the intrusions gave them an additional opportunity to infiltrate the institutions where the victims worked without their knowledge.
Extent of damage
The alert stated that the campaign infected at least 30,000 devices in more than 100 countries. In addition, funds or credentials were extracted from more than 7,000 cryptocurrency wallets during the period from December 2025 to July 2026.
The impact is not limited to stealing cryptocurrency; stolen personal documents can be used for identity theft, to help North Korea-linked individuals apply for jobs at foreign companies, or even to blackmail victims later.
Concerning indicators related to job-related infiltration
The alert pointed to a case in which a person suspected of having links to North Korea was applying for an engineering position at a Japanese cryptocurrency trading platform using a fake résumé. He was rejected after inconsistencies were found during the interview, including his inability to explain the skills listed in his résumé in detail.
Authorities also noted that the campaign is part of a broader pattern of North Korea attempts to use information technology personnel as a means to infiltrate foreign companies, with assessments suggesting that some of these personnel are connected to the country’s Ministry of Ammunition Industries.
How can companies and developers reduce risk?
This incident recommends taking stringent, practical measures—especially for development and hiring teams:
• Verify the identity of the hiring organization through independent channels before opening any files or links.
• Refuse to run any file sent as a technical test or urgent fix without prior security screening.
• Carefully review résumés and attached files, and test actual knowledge during interviews.
• Apply clear security policies on work devices, including limiting permissions and enabling multi-layer protection.
• Train employees on social engineering tactics related to hiring and freelancing.
This campaign underscores that fake job postings have become an effective tool in the hands of attackers—not only to steal digital assets, but also to breach institutions via the back door through the trust granted to hiring processes.
