VYPR
advisoryPublished Sep 18, 2026· 2 sources

North Korean 'WaterPlum' Hackers Target Job Seekers for Crypto and Data Theft

International security agencies have issued a warning about the North Korean hacking group WaterPlum, also known as Contagious Interview, which is targeting job seekers worldwide to steal cryptocurrency and sensitive data.

International security agencies have issued a stark warning regarding the activities of a North Korean hacking collective, identified as WaterPlum or Contagious Interview. This group is systematically targeting job seekers across the globe, particularly those in the burgeoning fields of artificial intelligence (AI) and cryptocurrency. By posing as legitimate employers, WaterPlum actors exploit the allure of attractive job opportunities to infiltrate the systems of unsuspecting candidates, ultimately aiming to pilfer sensitive personal information and illicitly acquire cryptocurrency.

The threat actors are known to impersonate well-established AI, cryptocurrency, and Non-Fungible Token (NFT) companies, and have also leveraged recruiting services to enhance their credibility. This deceptive approach allows them to gain the trust of potential victims, who are often highly skilled IT professionals and software developers. The agencies behind the alert have attributed the group's operations to the 313 General Bureau of the Munitions Industry Department, which operates under the Central Committee of the Workers Party of Korea, underscoring the state-sponsored nature of these cybercriminal activities.

Beyond their direct targeting of job seekers, some members of the WaterPlum group also operate as North Korean IT workers, engaging in web system design and development tasks for clients. This dual operational model allows them to both steal data and potentially gain access to corporate web systems. The alert, issued by agencies in Japan, Australia, and Germany, alongside the FBI and the Department of Defense's Cyber Crime Center, highlighted a significant overlap between WaterPlum's activities and those of North Korean IT workers, noting the use of identical IP addresses for accessing laptop farms and cloud-sourcing services.

Collectively, WaterPlum's operations have had a far-reaching impact, infecting an estimated 30,000 devices in over 100 countries. The primary targets include IT professionals in Japan, the United States, Europe, and other nations. The financial gains from these operations are substantial, with the group having successfully siphoned the equivalent of nearly $11 million in cryptocurrency from more than 7,000 crypto wallets and transferred it to North Korea.

Law enforcement agencies have reported some success in disrupting WaterPlum's operations. Notably, authorities in Japan successfully identified, investigated, and dismantled a "laptop farm" operated by an enabler within the country. This operation yielded evidence of significant cryptocurrency transfers to foreign locations. The FBI has also been actively identifying and prosecuting U.S.-based individuals who provide illicit facilitation services to North Korean IT workers, demonstrating a coordinated international effort to combat this threat.

This warning arrives concurrently with a report from the Multilateral Sanctions Monitoring Team, an international panel tasked with overseeing UN sanctions against North Korea. This report exposed the presence of thousands of North Korean nationals employed in various industries globally, many of whom are suspected of engaging in illicit cyber activities to circumvent sanctions and generate revenue for their regime.

The tactics employed by WaterPlum highlight a concerning trend of nation-state actors leveraging sophisticated social engineering and technical exploits to fund their operations. By targeting individuals seeking employment, the group exploits a common and often vulnerable human desire for career advancement, making their attacks particularly insidious. The scale of their operations, impacting tens of thousands of devices and millions of dollars, underscores the significant threat posed by North Korean cybercrime syndicates.

Security agencies are urging vigilance among job seekers, particularly those in high-demand tech sectors, to be wary of unsolicited job offers and to rigorously vet potential employers. Enhanced cybersecurity practices, including multi-factor authentication and careful scrutiny of communication channels, are crucial defenses against such targeted phishing and social engineering campaigns.

This updated advisory provides a more precise financial impact, attributing at least $10.71 million in thefts to the WaterPlum campaign, with funds directly supporting the North Korean regime. It also details how stolen credentials and identity documents are leveraged for further impersonation, extortion, and to exfiltrate crypto assets and trade secrets from victims' employers or clients.

Synthesized by Vypr AI