started · updated
WaterPlum cyber group steals $10.7M via fake recruitment scams
A joint advisory from authorities in the United States, Japan, Germany, and Australia has identified a North Korean-linked cyber group, known as WaterPlum or Contagious Interview, for a massive cryptocurrency theft operation. Between December 2025 and July 2026, the group reportedly stole at least $10.71 million by targeting IT professionals, software developers, and Web3 specialists.
The group utilized sophisticated social engineering tactics, impersonating recruiters from AI, cryptocurrency, and NFT companies. To enhance their credibility during video interviews, attackers employed AI face-swapping technology. Victims were lured into downloading malicious files, disguised as coding tests or technical fixes, which infected more than 30,000 devices across over 100 countries.
Investigators have linked the group specifically to the 313th General Bureau of the Munitions Industry Department under the Workers' Party of Korea. The operation affected over 7,000 cryptocurrency wallets. In a notable breakthrough, Japanese authorities dismantled a laptop farm used by the group to simulate local presence during remote operations. Identified malware families used in the campaign include BeaverTail, InvisibleFerret, and OtterCookie.
Entities
Australian Signals Directorate · FBI · Japan National Police Agency · North Korea · Waterplum
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] Authorities in Japan dismantled a laptop farm used to make remote operators appear as if they were locally based. www.blogspan.net
- [● 3 SOURCES] More than 30,000 devices were infected across over 100 countries. www.ad-hoc-news.de · www.blogspan.net
- [● 3 SOURCES] The group stole at least $10.71 million in cryptocurrency. www.blogspan.net · www.ibtimes.co.uk
- [○ 1 SOURCE] Over 7,000 cryptocurrency wallets were affected between December 2025 and July 2026.
- [● 4 SOURCES] The North Korean-linked cyber group WaterPlum (also known as Contagious Interview) conducted the operation. www.ad-hoc-news.de · www.blogspan.net · www.ibtimes.co.uk
- [● 2 SOURCES] The attackers used AI face-swapping technology to impersonate employers during video calls. www.ad-hoc-news.de · www.ibtimes.co.uk
- [○ 1 SOURCE] The group is attributed to the 313th General Bureau of the Munitions Industry Department under the Workers' Party of Korea. www.blogspan.net
- [○ 1 SOURCE] The campaign utilized specific malware families including BeaverTail, InvisibleFerret, and OtterCookie. www.blogspan.net