Security agencies from the United States, Japan, Australia and Germany have jointly identified a North Korea-linked hacking campaign that stole at least $10.7 million from cryptocurrency wallets by luring software developers and IT specialists with fake job offers. The operation, tracked by researchers under the name WaterPlum and also known as Contagious Interview, compromised more than 30,000 devices and drained over 7,000 crypto wallets across more than 100 countries between December 2025 and July 2026.

According to the advisory, the campaign targeted developers and IT professionals directly, exploiting the recruitment process itself as the point of entry. Victims were approached with job offers and, during the hiring process, induced to run code or download materials that installed malware on their systems. Researchers have documented five malware variants used in the operation: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.

Once installed, the malware harvested browser credentials, clipboard content, screenshots, keystrokes and locally stored files. It also targeted crypto wallet private keys and recovery phrases, along with identity documents such as passport images.

Fake interviews and falsified credentials

Part of the deception relied on manipulating video interviews directly. Operatives are said to have used AI-based facial manipulation technology during calls with prospective employers, later disabling their cameras and citing technical issues to avoid closer scrutiny. In one case cited by investigators, a suspected North Korean IT operative applied for a software engineer position at a Japanese crypto exchange platform using falsified credentials.

The campaign's reach extended into established firms in the sector. ConsenSys disclosed in July that it had unknowingly hired a developer linked to North Korea as a consultant. The company said it revoked the individual's system access once the link was discovered, and that a subsequent investigation found no misappropriation of assets, data exfiltration, malicious code insertion, or compromise of user security.

Links to North Korea's military-industrial complex

US and Japanese intelligence agencies assess that WaterPlum members, along with some North Korean IT professionals operating abroad, work under an organisational unit connected to the country's military-industrial complex. The advisory does not detail how the stolen funds were subsequently used.

Authorities are urging job seekers, particularly in software development and IT roles, to avoid running code or downloading materials from unverified recruitment sources. Anyone who suspects their device may have been compromised is advised to isolate it from the network immediately, given the scale and persistence of the campaign documented across more than 100 countries.