North Korean WaterPlum Group Infects 30,000 Devices Globally with Malware via Fake Job Interviews

Why it matters
This campaign highlights the increasing sophistication of state-sponsored cyber threats targeting professionals worldwide.
What happened (in 30 seconds)
- North Korean WaterPlum group executed a global malware campaign, infecting over 30,000 devices by September 2026.
- Fake job interviews were used to lure software developers and IT professionals into downloading malicious code.
- Over $10.71 million in cryptocurrency was stolen, impacting more than 7,000 wallets.
The context you actually need
- International sanctions on North Korea have pushed the regime to rely on cyber operations for revenue, particularly through cryptocurrency theft.
- The Contagious Interview campaign is part of a broader strategy linked to the Lazarus Group, known for targeting financial institutions since the 2010s.
- The tactic of impersonating recruiters emerged in late 2022, with significant activity documented by cybersecurity experts in subsequent years.
What's really happening
The WaterPlum group's malware campaign, dubbed "Contagious Interview," is a calculated effort by North Korean state-sponsored actors to exploit vulnerabilities in the global job market, particularly among tech professionals. With North Korea facing stringent international sanctions that limit its ability to generate revenue through conventional means, cyber operations have become a vital source of foreign currency. This campaign specifically targets software developers and IT professionals, who are often in high demand and may be more susceptible to job-related scams.
The operation began gaining traction in December 2022, with researchers identifying the use of various malware strains, including BeaverTail and InvisibleFerret, delivered through fake coding assignments during interviews. By 2025, the campaign had expanded to include macOS variants, indicating a strategic adaptation to target a broader range of potential victims. The introduction of new malware families, such as OtterCookie in 2026, demonstrates the group's ongoing evolution and commitment to refining their tactics.
The joint advisory issued by authorities from Japan, the United States, Australia, and Germany in September 2026 confirmed the widespread impact of this campaign, with infections reported in over 100 countries. The exfiltration of approximately $10.71 million in cryptocurrency underscores the financial implications of this cyber threat, as it directly funds the North Korean regime. The use of platforms like GitHub and npm repositories to host malicious code adds a layer of complexity, as these are legitimate tools widely used by developers, making it easier for attackers to disguise their operations.
As the campaign continues to unfold, organizations and platforms hosting code repositories are urged to remain vigilant and monitor for malicious packages. The ongoing nature of this threat highlights the need for heightened awareness among job seekers in the technology sector, as the tactics employed by the WaterPlum group could evolve further, potentially leading to even greater financial losses and security breaches.
Who feels it first (and how)
- Software developers: Targeted through fake job interviews, risking device security and personal data.
- IT professionals: Vulnerable to malware that can compromise work-related systems and sensitive information.
- Cryptocurrency investors: Directly impacted by the theft of funds from compromised wallets.
- Recruitment agencies: May face reputational damage if associated with compromised job offers.
- Global tech firms: Could experience disruptions and financial losses due to compromised employees and systems.
What to watch next
- Increased cybersecurity measures: Look for tech companies to enhance security protocols in response to this threat, which could lead to new industry standards.
- Emergence of new malware variants: Monitor for reports of additional malware families as the WaterPlum group adapts its tactics.
- Regulatory responses: Watch for potential regulatory changes aimed at protecting job seekers and enhancing cybersecurity in the tech sector.
The WaterPlum group's campaign has infected over 30,000 devices and stolen $10.71 million in cryptocurrency.
The campaign will continue to evolve, with new tactics and malware variants emerging.
The long-term impact on the job market and cybersecurity regulations in response to this campaign.
Frequently Asked Questions
- Why it matters?
- This campaign highlights the increasing sophistication of state-sponsored cyber threats targeting professionals worldwide.
- What happened (in 30 seconds)?
- North Korean WaterPlum group executed a global malware campaign, infecting over 30,000 devices by September 2026. Fake job interviews were used to lure software developers and IT professionals into downloading malicious code. Over $10.71 million in cryptocurrency was stolen, impacting more than 7,000 wallets.
- What's really happening?
- The WaterPlum group's malware campaign, dubbed "Contagious Interview," is a calculated effort by North Korean state-sponsored actors to exploit vulnerabilities in the global job market, particularly among tech professionals. With North Korea facing stringent international sanctions that limit its ability to generate revenue through conventional means, cyber operations have become a vital source of foreign currency. This campaign specifically targets software developers and IT professionals, who
- Who feels it first (and how)?
- Software developers: Targeted through fake job interviews, risking device security and personal data. IT professionals: Vulnerable to malware that can compromise work-related systems and sensitive information. Cryptocurrency investors: Directly impacted by the theft of funds from compromised wallets. Recruitment agencies: May face reputational damage if associated with compromised job offers. Global tech firms: Could experience disruptions and financial losses due to compromised employee
- What to watch next?
- Increased cybersecurity measures: Look for tech companies to enhance security protocols in response to this threat, which could lead to new industry standards. Emergence of new malware variants: Monitor for reports of additional malware families as the WaterPlum group adapts its tactics. Regulatory responses: Watch for potential regulatory changes aimed at protecting job seekers and enhancing cybersecurity in the tech sector.
Consumer tech news, reviews, and buying guides for gadgets and electronics.
"TechRadar is known for comprehensive buying advice, hardware reviews, and consumer tech news targeted at mainstream audiences."
— A47 Editor
North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews
A North Korean cybercriminal group, dubbed the 'Contagious Interview' gang, has reportedly targeted over 30,000 businesses worldwide by deploying malware through fake job interviews. This scheme has allowed them to steal millions from unsuspecting vi...
Tech news, hardware, and AI tools coverage.
"PC/tech site increasingly covering AI hardware and apps."
— A47 Editor
Hackers use fake coding tests to infect 30,000 devices and steal $10 million in crypto
A group identified as WaterPlum, linked to North Korean hackers, has reportedly infected 30,000 devices by posing as recruiters and sending fake coding tests to web designers, software engineers, and cryptocurrency professionals. This scheme has resu...
Covers blockchain, cryptocurrency news, project analysis, and market insights.
"Cointelegraph is a leading crypto-focused media outlet known for timely news, analysis, and educational content related to blockchain and digital assets."
— A47 Editor
North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
A North Korean cyber group known as WaterPlum has successfully targeted developers by offering fake job opportunities in the cryptocurrency, AI, and NFT sectors, leading to the infection of over 30,000 devices across more than 100 countries and the t...
English-language digital publication covering business, politics, technology, and current affairs.
"The Arabian Post mixes original and syndicated-style coverage with a broad regional and global business-news orientation."
— A47 Editor
WaterPlum compromises 30,000 devices through fake interviews
North Korean cyber operators, identified as WaterPlum, have compromised over 30,000 devices across more than 100 countries through fraudulent job interviews aimed at technology professionals. This campaign, also known as Contagious Interview, specifi...