A North Korea-linked cyber campaign posing as prospective employers compromised at least 30,000 computers and extracted $10.71 million in cryptocurrency, according to a multinational security advisory published on September 18. The operation, tracked as WaterPlum or Contagious Interview, targeted technology professionals through fraudulent recruitment processes rather than conventional phishing alone, reaching victims in more than 100 countries between December 2025 and July 2026.
The joint security advisory from the FBI and partner agencies says WaterPlum impersonated legitimate AI, cryptocurrency and NFT companies while approaching software developers and other IT professionals through recruiting services and online employment platforms. Authorities linked the campaign to more than 7,000 cryptocurrency wallets from which funds or account credentials were taken, with at least 1.7 billion Japanese yen, equivalent to $10.71 million, ultimately transferred on behalf of North Korea.
Fake Coding Tests Delivered Persistent Malware
The attack chain relied heavily on normal-looking technical interviews. During recruitment, victims were instructed to download and execute files presented as coding assignments or fixes for supposed video-conferencing problems. Those files could contain malicious NPM packages carrying malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
Once initial access was established, the attackers used remote-access trojans to maintain connectivity and persistence inside compromised systems. The resulting access gave WaterPlum a path to sensitive information, credentials and cryptocurrency-related data without requiring every victim to expose a private key directly during the fake interview. Authorities specifically warn that stolen credentials can later be used to extract crypto assets, personal data and trade secrets from victims or the organizations they work with.
The campaign primarily targeted web designers, engineers and specialists working in cryptocurrency, blockchain and Web3. That victim profile makes the recruitment vector particularly effective because developers are routinely expected to clone repositories, run unfamiliar code and complete technical exercises during legitimate hiring processes. Microsoft had separately documented the broader Contagious Interview pattern earlier in 2026, including malicious code delivered through fake developer interviews.
Wallet Losses Extend Beyond Endpoint Infection
The financial impact should also be distinguished from the raw number of compromised machines. Thirty thousand infected devices does not mean 30,000 wallets were drained, as the government advisory separately identifies more than 7,000 wallets associated with stolen funds or account credentials. The $10.71 million figure represents cryptocurrency exfiltrated from victims during the documented period, rather than an estimate derived simply from the number of infections.
For users who suspect compromise, the advisory recommends treating wallet information as potentially exposed even after malware removal. Authorities advise creating a new wallet on a separate device, transferring remaining assets and storing the new seed phrase offline, alongside isolating affected machines and avoiding execution of untrusted code on systems that handle cryptocurrency or sensitive information.
The next concrete milestone will be whether authorities disclose additional attribution, recovered funds or updated victim counts as investigations continue. For now, the confirmed scale is at least 30,000 compromised devices, more than 7,000 affected cryptocurrency wallets and $10.71 million in crypto exfiltrated during an eight-month campaign, making WaterPlum a significant example of recruitment workflows being weaponized against developers and crypto professionals.
