International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

North Korean Hackers Target Job Seekers, Steal Crypto and Data on a Massive Scale

A group of North Korean hackers has been infiltrating the computer networks of tens of thousands of job seekers worldwide by posing as prospective employers. The hackers, known as WaterPlum or Contagious Interview, have stolen sensitive information and millions of dollars worth of cryptocurrency from unsuspecting individuals.

The group’s tactics are straightforward: they pose as legitimate companies in the AI, cryptocurrency, or NFT industries, offering attractive job opportunities to software developers and IT professionals. In reality, they’re using these ruses to gain access to victims’ computer networks, where they can siphon off valuable data and cryptocurrencies.

But that’s not all – WaterPlum actors have also been operating as North Korean IT workers, performing web system design and development tasks on corporate web systems for clients. This overlap between the group’s operations is substantial, with the same IP addresses being used to access laptop farms, cloud-sourcing services, and apply for positions at cryptocurrency exchanges.

The scope of WaterPlum’s activities is staggering. The group has infected more than 30,000 devices in over 100 countries, targeting IT professionals in Japan, the United States, Europe, and other nations. Its operations have transferred nearly $11 million worth of cryptocurrency from over 7,000 crypto wallets to North Korea.

International security agencies, including those in Japan, Australia, Germany, the FBI, and the Department of Defense’s Cyber Crime Center, are warning about WaterPlum’s tactics. They’ve had some success tackling the group, but more cooperation is needed to take down the operation. The agencies have released details about WaterPlum’s tactics, techniques, and procedures in an effort to raise awareness and prevent further attacks.

The warning comes at a time when the international community is increasingly concerned about North Korea’s cyber activities. A recent report by the Multilateral Sanctions Monitoring Team exposed thousands of North Korean nationals employed in industries around the world, highlighting the scale of Pyongyang’s illicit operations.

So what can job seekers do to protect themselves? The most important thing is to be cautious when responding to unsolicited job offers. Legitimate companies will never ask for sensitive information or cryptocurrency transfers as part of a job application process. Always verify the company’s identity and check for reviews from other employees before accepting an offer. And if you’re unsure, trust your instincts – it’s better to err on the side of caution when dealing with potential cyber threats.

In today’s digital age, cybersecurity is everyone’s responsibility. By being aware of the tactics used by WaterPlum and other groups like them, we can all play a role in protecting ourselves and our communities from the threat of North Korean hackers.


Source: CyberScoop — 2026-09-18