North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
Source Entity
Cointelegraph by Felix Ng

The North Korean hacking group WaterPlum has compromised 30,000 devices across 100 countries using fake job offers. The operation, which successfully stole $10.7 million, targeted tech professionals in the crypto and AI sectors.
The Rise of State-Sponsored Cyber Espionage: The WaterPlum Operation
Recent reports have unveiled a sophisticated, large-scale cyber operation orchestrated by the North Korean hacking entity known as WaterPlum, also identified as 'Contagious Interview.' By masquerading as legitimate recruiters, these actors successfully infiltrated at least 30,000 devices across more than 100 countries. This campaign specifically targeted software developers, web designers, and IT specialists, leveraging the allure of opportunities in high-growth sectors like artificial intelligence, blockchain, and non-fungible tokens (NFTs) to deliver malicious payloads.
Tactical Deception and Global Reach
The success of the WaterPlum campaign lies in its high degree of professional mimicry. By impersonating established firms and utilizing existing recruiting platforms, the group exploited the trust inherent in the tech hiring ecosystem. The sheer geographic scope—spanning over 100 nations—highlights a deliberate effort to cast a wide net, ensuring that even if a small percentage of targeted professionals engage with the fake job offers, the cumulative impact is significant. This strategy effectively turns the professional aspirations of developers into a vector for state-sponsored digital espionage.
The Financial Impact and Economic Motivation
Beyond the disruption of individual devices, the primary objective of WaterPlum appears to be financial gain and intellectual property theft. The group has successfully siphoned at least $10.7 million in cryptocurrency, a figure that underscores the lucrative nature of these cyber-crimes. Given North Korea's history of utilizing illicit cyber activities to bypass international sanctions and fund state operations, this theft is not merely a criminal nuisance but a strategic component of national economic policy.
International Coordination and Attribution
This campaign has prompted a rare and necessary display of international cooperation. A joint advisory issued by authorities in Japan, Germany, Australia, and the United States serves as a critical acknowledgment of the threat posed by these actors. This coordinated response is vital, as it standardizes the intelligence-sharing process, allowing international security agencies to better track the infrastructure used by WaterPlum and provide actionable guidance to software developers and companies alike.
Future Trends in Cyber-Recruitment Threats
Looking ahead, the WaterPlum operation signals a shift toward more targeted, social-engineering-heavy cyberattacks. As AI continues to evolve, the ability for threat actors to generate realistic job postings and professional communications will only improve. Organizations and individual professionals must adopt a 'zero-trust' approach to recruitment processes, particularly when interacting with entities that lack verifiable business histories or clear digital footprints. The legacy of this event will likely be a permanent increase in caution within the global tech hiring market, as the industry grapples with the reality that a dream job offer may be a sophisticated digital trap.