
Multi-Nation Investigation Reveals Over 30,000 Infected Devices and $10.71 Million Stolen in Global Crypto Scheme
A joint cybersecurity advisory published on cyber.gov.au on September 18, 2026, has detailed a massive cyberattack campaign conducted by North Korean hackers operating under the name WaterPlum (more widely known as Contagious Interview). Between December 2025 and July 2026, the group infected more than 30,000 devices across over 100 countries, stealing approximately $10.71 million in cryptocurrency.
The advisory was issued jointly by international agencies, including Japan’s National Police Agency and National Cybersecurity Office, the FBI, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution. Over the course of the eight-month campaign, WaterPlum compromised more than 7,000 cryptocurrency wallets and funneled roughly 1.7 billion Japanese yen back to North Korea.
Staged Hiring Processes and Malware Distribution
Tracked by security researchers since 2023 for combining financially motivated theft with cyberespionage, WaterPlum has been linked to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers’ Party of Korea. The group targets software developers and IT professionals by posing as recruiters for real artificial intelligence, cryptocurrency, and NFT companies through social media, job boards, freelance marketplaces, and gig-work platforms.
During staged virtual technical interviews or coding assignments, attackers instruct candidates to download files disguised as test tasks or fixes for videoconferencing glitches, which covertly install malware. Once active, the malware harvests browser passwords, screenshots, stored files, and cryptocurrency-wallet data, while deploying remote-access trojans. Furthermore, infected laptops can serve as footholds into victim employer networks, enabling the exfiltration of trade secrets, personal data, and crypto assets, or providing leverage for extortion.
The advisory also addresses related schemes involving North Korean IT workers utilizing remote “laptop farms” to infiltrate domestic cryptocurrency exchanges and generate foreign currency for the regime. The full advisory is hosted by the FBI’s Internet Crime Complaint Center alongside publications from partnering international agencies.