International Cyber Advisory Exposes North Korean “WaterPlum” Fake Interview Campaign Targeting IT Professionals

by Dimitri Dimitrov Published on September 22, 2026
Editorial Standards

☆ Editorial Standards

All news content is produced by qualified journalists and analysts under a published editorial code requiring accuracy, source verification, and editorial review prior to publication.

Advertisers and commercial partners have no influence over news coverage.


News editorial policy · Contact us
✓ Fact-Checked

✓ Fact-Checked

Every article undergoes senior editorial review.

Regulatory and legal reporting is cross-referenced against primary sources including official government and regulatory authority records.

Corrections are issued transparently with a visible update notice.


News fact-check policy
⊘ Independence

⊘ Independence

Gamblers Connect is a B2B iGaming media platform.

Editorial decisions, including what to cover, how to cover it, and what to publish, are made independently by our newsroom.

Commercial partners may purchase publication frequency but cannot influence editorial tone, angle, or content.


News independence policy
↗ Commercial Disclosure

↗ Commercial Disclosure

Gamblers Connect is a B2B media platform. We generate revenue through subscriptions, B2B referral partnerships, directory listings, advertising, and media services.

Gamblers Connect is not a licensed gambling operator, affiliate, or player acquisition channel in any jurisdiction.

We do not earn revenue from player activity, wagers, or deposits.


News commercial disclosure · Contact us
google gemini cybersecurity testing hack 01 1
Key Takeaways
⏱ 2 min read
1
Global Scale — North Korean hacking group WaterPlum infected over 30,000 devices across more than 100 countries between December 2025 and July 202
2
Substantial Thefts — The campaign compromised over 7,000 cryptocurrency wallets, stealing roughly $10.71 million and transferring 1.7 billion Japanese yen back to North Korea
3
Fake Interview Tactics — Attackers lured software developers and IT professionals through staged hiring processes on freelance and job platforms, deploying malware via fake coding tests and video conferencing fixes
4
Multi-Agency Advisory — Intelligence and cybersecurity authorities from the US, UK, Australia, Germany, and Japan published the joint warning on September 18, 2026

Multi-Nation Investigation Reveals Over 30,000 Infected Devices and $10.71 Million Stolen in Global Crypto Scheme

A joint cybersecurity advisory published on cyber.gov.au on September 18, 2026, has detailed a massive cyberattack campaign conducted by North Korean hackers operating under the name WaterPlum (more widely known as Contagious Interview). Between December 2025 and July 2026, the group infected more than 30,000 devices across over 100 countries, stealing approximately $10.71 million in cryptocurrency.

The advisory was issued jointly by international agencies, including Japan’s National Police Agency and National Cybersecurity Office, the FBI, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution. Over the course of the eight-month campaign, WaterPlum compromised more than 7,000 cryptocurrency wallets and funneled roughly 1.7 billion Japanese yen back to North Korea.

Staged Hiring Processes and Malware Distribution

Tracked by security researchers since 2023 for combining financially motivated theft with cyberespionage, WaterPlum has been linked to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers’ Party of Korea. The group targets software developers and IT professionals by posing as recruiters for real artificial intelligence, cryptocurrency, and NFT companies through social media, job boards, freelance marketplaces, and gig-work platforms.

During staged virtual technical interviews or coding assignments, attackers instruct candidates to download files disguised as test tasks or fixes for videoconferencing glitches, which covertly install malware. Once active, the malware harvests browser passwords, screenshots, stored files, and cryptocurrency-wallet data, while deploying remote-access trojans. Furthermore, infected laptops can serve as footholds into victim employer networks, enabling the exfiltration of trade secrets, personal data, and crypto assets, or providing leverage for extortion.

The advisory also addresses related schemes involving North Korean IT workers utilizing remote “laptop farms” to infiltrate domestic cryptocurrency exchanges and generate foreign currency for the regime. The full advisory is hosted by the FBI’s Internet Crime Complaint Center alongside publications from partnering international agencies.

Dimitri Dimitrov

Dimitri is an iGaming expert with nearly a decade of experience and a knack for crafting content that speaks directly to the iGaming crowd. He understands affiliate marketing, player psychology, and search algorithms, which enables him to write engaging, data-driven articles.

Sources
1 source verified before publication. This news is an official press release that traces directly to official documents by the Australian Cyber Security Centre (ACSC). How we verify sources →
Gamblers Connect only publishes verified and official news from reputable government organizations. Read our full editorial standards →
Mentioned in this Article