< Back to all clusters
[TECHNOLOGY] · United States, Australia, Germany, Japan · 3 sources

started · updated

North Korean hackers steal $10.71 million via fake job offers

A cyberattack campaign linked to North Korea, identified as ‘WaterPlum’ and known as ‘Contagious Interview’, has compromised over 30,000 devices across more than 100 countries. Operating between December 2025 and July 2026, the group utilized fraudulent job offers and technical interviews to infect computers with malware.

The attackers targeted technology professionals, including software engineers, developers, and specialists in AI, blockchain, and Web3. By posing as recruiters on platforms like LinkedIn, the group offered remote positions with competitive salaries. During the technical assessment phase, victims were prompted to download repositories or execute code that installed malware, granting attackers persistent remote access.

This operation resulted in the compromise of more than 7,000 cryptocurrency wallets, with at least $10.71 million in digital assets moved to addresses under the group's control. Security authorities in the United States, Australia, Germany, and Japan have issued joint alerts regarding the campaign, noting that the malware allows for the theft of credentials, keystrokes, and confidential documents.

Entities

Contagious Interview · North Korea · Waterplum