
If you’re a software developer who received a suspicious job offer in the past year, there’s a non-trivial chance it came from North Korea. A cyber group called WaterPlum, also tracked as Contagious Interview, has been running a large-scale fake recruitment operation that infected at least 30,000 devices and drained over $10.7 million from cryptocurrency wallets. According to Cointelegraph, a joint advisory from Japan, Germany, Australia, and the United States linked the campaign to North Korea’s Munitions Industry Department, placing it squarely within the state’s weapons-funding infrastructure.
The operation targeted web designers, software engineers, and specialists in cryptocurrency, blockchain, and Web3. WaterPlum actors posed as recruiters for legitimate crypto companies, AI firms, and NFT projects, reaching victims through LinkedIn, freelance marketplaces, gig platforms, and job boards. Once contact was established, victims were told to download files as part of a coding test or to fix a supposed video-conferencing error. Those files were malware. Simple as that.
After gaining backdoor access, the attackers deployed remote-access trojans and infostealers to pull sensitive data and cryptocurrency off compromised machines. Between December 2025 and July 2026, credentials and funds were extracted from more than 7,000 crypto wallets. But the damage didn’t stop at stolen coins. Stolen identity documents were used to let North Korean IT workers impersonate victims, earn income under false identities, and in some cases, extort the original targets with the sensitive information collected.
The threat also bleeds into organizations that hire the developers who got compromised. When a developer’s machine is infected, their employer’s internal systems become a potential entry point too. This is not a narrow problem affecting careless individuals. It’s a supply-chain-style attack on the broader tech workforce.
The advisory described one case where a suspected North Korean worker applied for an engineering role at a Japanese crypto exchange using a forged resume. The exchange caught him during the interview when he couldn’t explain the skills listed on his own CV. That’s the low-end outcome. In a more concerning incident, Consensys unknowingly hired a North Korea-linked developer as a consultant. The company said it cut the person’s access after identifying the threat and found no theft, no malicious code deployment, and no impact on users. But the fact that the person got in at all is the point.
This campaign fits into a pattern that’s been building for years. North Korea has used crypto theft as a primary funding mechanism for its weapons programs, and authorities in the US have been warning about its undercover IT workers since at least 2018. The FBI attributed the $1.5 billion Bybit hack in February 2025 to North Korean actors. WaterPlum’s operation is not an anomaly. It’s part of a well-resourced, state-directed strategy that keeps adapting.
For anyone in the crypto or Web3 space, the privacy implications here are worth taking seriously. The attack vectors are:
- Fake job listings on legitimate platforms like LinkedIn and freelance marketplaces
- Malicious files disguised as coding assignments or video-conferencing fixes
- Remote-access trojans that give persistent backdoor access to your machine
- Infostealers targeting crypto wallet credentials and personal documents
- Identity theft used to impersonate victims and access further systems
The advice sounds basic, but it matters: never run code sent by a recruiter you haven’t independently verified. Check company domains. Don’t install packages you don’t understand. And if something about a job offer feels off, trust that instinct. North Korea is counting on people ignoring it.