Trending

    North Korean WaterPlum Group Infects 30,000 Devices Globally with Malware via Fake Job Interviews

    Section editor: ·Moderate4 articles covering this·4 news sources·Updated 2 hours ago·World
    Share:
    Infographic showing North Korean malware campaign's impact on global tech professionals and cryptocurrency theft.

    Why it matters

    This campaign highlights the increasing sophistication of state-sponsored cyber threats targeting professionals worldwide.

    What happened (in 30 seconds)

    • North Korean WaterPlum group executed a global malware campaign, infecting over 30,000 devices by September 2026.
    • Fake job interviews were used to lure software developers and IT professionals into downloading malicious code.
    • Over $10.71 million in cryptocurrency was stolen, impacting more than 7,000 wallets.

    The context you actually need

    • International sanctions on North Korea have pushed the regime to rely on cyber operations for revenue, particularly through cryptocurrency theft.
    • The Contagious Interview campaign is part of a broader strategy linked to the Lazarus Group, known for targeting financial institutions since the 2010s.
    • The tactic of impersonating recruiters emerged in late 2022, with significant activity documented by cybersecurity experts in subsequent years.

    What's really happening

    The WaterPlum group's malware campaign, dubbed "Contagious Interview," is a calculated effort by North Korean state-sponsored actors to exploit vulnerabilities in the global job market, particularly among tech professionals. With North Korea facing stringent international sanctions that limit its ability to generate revenue through conventional means, cyber operations have become a vital source of foreign currency. This campaign specifically targets software developers and IT professionals, who are often in high demand and may be more susceptible to job-related scams.

    The operation began gaining traction in December 2022, with researchers identifying the use of various malware strains, including BeaverTail and InvisibleFerret, delivered through fake coding assignments during interviews. By 2025, the campaign had expanded to include macOS variants, indicating a strategic adaptation to target a broader range of potential victims. The introduction of new malware families, such as OtterCookie in 2026, demonstrates the group's ongoing evolution and commitment to refining their tactics.

    The joint advisory issued by authorities from Japan, the United States, Australia, and Germany in September 2026 confirmed the widespread impact of this campaign, with infections reported in over 100 countries. The exfiltration of approximately $10.71 million in cryptocurrency underscores the financial implications of this cyber threat, as it directly funds the North Korean regime. The use of platforms like GitHub and npm repositories to host malicious code adds a layer of complexity, as these are legitimate tools widely used by developers, making it easier for attackers to disguise their operations.

    As the campaign continues to unfold, organizations and platforms hosting code repositories are urged to remain vigilant and monitor for malicious packages. The ongoing nature of this threat highlights the need for heightened awareness among job seekers in the technology sector, as the tactics employed by the WaterPlum group could evolve further, potentially leading to even greater financial losses and security breaches.

    Who feels it first (and how)

    • Software developers: Targeted through fake job interviews, risking device security and personal data.
    • IT professionals: Vulnerable to malware that can compromise work-related systems and sensitive information.
    • Cryptocurrency investors: Directly impacted by the theft of funds from compromised wallets.
    • Recruitment agencies: May face reputational damage if associated with compromised job offers.
    • Global tech firms: Could experience disruptions and financial losses due to compromised employees and systems.

    What to watch next

    • Increased cybersecurity measures: Look for tech companies to enhance security protocols in response to this threat, which could lead to new industry standards.
    • Emergence of new malware variants: Monitor for reports of additional malware families as the WaterPlum group adapts its tactics.
    • Regulatory responses: Watch for potential regulatory changes aimed at protecting job seekers and enhancing cybersecurity in the tech sector.
    Known:

    The WaterPlum group's campaign has infected over 30,000 devices and stolen $10.71 million in cryptocurrency.

    Likely:

    The campaign will continue to evolve, with new tactics and malware variants emerging.

    Unclear:

    The long-term impact on the job market and cybersecurity regulations in response to this campaign.

    Frequently Asked Questions

    Why it matters?
    This campaign highlights the increasing sophistication of state-sponsored cyber threats targeting professionals worldwide.
    What happened (in 30 seconds)?
    North Korean WaterPlum group executed a global malware campaign, infecting over 30,000 devices by September 2026. Fake job interviews were used to lure software developers and IT professionals into downloading malicious code. Over $10.71 million in cryptocurrency was stolen, impacting more than 7,000 wallets.
    What's really happening?
    The WaterPlum group's malware campaign, dubbed "Contagious Interview," is a calculated effort by North Korean state-sponsored actors to exploit vulnerabilities in the global job market, particularly among tech professionals. With North Korea facing stringent international sanctions that limit its ability to generate revenue through conventional means, cyber operations have become a vital source of foreign currency. This campaign specifically targets software developers and IT professionals, who
    Who feels it first (and how)?
    Software developers: Targeted through fake job interviews, risking device security and personal data. IT professionals: Vulnerable to malware that can compromise work-related systems and sensitive information. Cryptocurrency investors: Directly impacted by the theft of funds from compromised wallets. Recruitment agencies: May face reputational damage if associated with compromised job offers. Global tech firms: Could experience disruptions and financial losses due to compromised employee
    What to watch next?
    Increased cybersecurity measures: Look for tech companies to enhance security protocols in response to this threat, which could lead to new industry standards. Emergence of new malware variants: Monitor for reports of additional malware families as the WaterPlum group adapts its tactics. Regulatory responses: Watch for potential regulatory changes aimed at protecting job seekers and enhancing cybersecurity in the tech sector.
    4 Articles
    TechRadar

    North Korean 'Contagious Interview' gang hits 30,000 businesses across the world with malware following fake interviews

    A North Korean cybercriminal group, dubbed the 'Contagious Interview' gang, has reportedly targeted over 30,000 businesses worldwide by deploying malware through fake job interviews. This scheme has allowed them to steal millions from unsuspecting vi...

    16 hours ago
    Read Full Article
    TechSpot

    Hackers use fake coding tests to infect 30,000 devices and steal $10 million in crypto

    A group identified as WaterPlum, linked to North Korean hackers, has reportedly infected 30,000 devices by posing as recruiters and sending fake coding tests to web designers, software engineers, and cryptocurrency professionals. This scheme has resu...

    19 hours ago
    Read Full Article
    Cointelegraph

    North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    A North Korean cyber group known as WaterPlum has successfully targeted developers by offering fake job opportunities in the cryptocurrency, AI, and NFT sectors, leading to the infection of over 30,000 devices across more than 100 countries and the t...

    The Arabian Post

    WaterPlum compromises 30,000 devices through fake interviews

    North Korean cyber operators, identified as WaterPlum, have compromised over 30,000 devices across more than 100 countries through fraudulent job interviews aimed at technology professionals. This campaign, also known as Contagious Interview, specifi...