North Korean Hackers Infect 30,000 Devices and Steal Crypto
WaterPlum, also known as Contagious Interview, tricked developers through fake job postings and stole wallet keys and browser data that way. The FBI and Japanese police link the campaign to at least $10.71 million in crypto.

Key Takeaways
- A North Korean hacking group infected more than 30,000 computers in over 100 countries and stole data from more than 7,000 crypto wallets.
- Between December 2025 and July 2026, at least $10.71 million in digital assets ended up in wallets controlled by the group.
- The group lured victims through fake job postings and malware, which is especially dangerous for crypto users and developers.
A North Korean hacking group has infected more than 30,000 computers in over 100 countries and stolen data from more than 7,000 crypto wallets. According to Japan’s National Police Agency and the FBI, at least $10.71 million (€9.3 million) in digital assets ended up in wallets controlled by the group between December 2025 and July 2026. The attack shows how quickly fake job applications and malware can still turn into a direct risk for crypto users and developers.
Fake Job Postings as Bait
The group, which authorities call WaterPlum and is also known as Contagious Interview, poses as a recruiter for companies in AI, crypto, and NFTs. Through social media, job boards, and freelance marketplaces, the group approaches software developers and IT workers with seemingly attractive job offers.
Victims are then given a technical interview round or a coding test. They are asked to download files from code-sharing sites, supposedly because a video call is broken or because the assignment requires it. Those files contain malware that tries to steal browser passwords, screenshots, keystrokes, and the secret keys of a crypto wallet.
Authorities warn that attacks like this are especially dangerous because the attacker acts like a normal employer. At first, the contact seems legitimate to victims, while the damage only becomes visible later.
A Bigger Pattern of North Korean Hacks
This case fits into a broader wave of North Korean cyberattacks on the crypto sector. North Korean hackers were previously linked to major thefts, including the attack on Bybit in February 2025. According to earlier estimates, North Korea stole a total of $2.02 billion (€1.8 billion) in crypto in 2025, accounting for nearly 60% of all reported crypto theft that year.
That makes it clear why regulators and law enforcement agencies are warning more often about social engineering instead of just technical bugs. The attackers are not only targeting wallets, but also people who have access to code, accounts, and company networks.
Why This Matters for Europe
For European crypto users and companies, this is especially relevant because the attack shows how international these campaigns are. The group hit victims in more than 100 countries and also used Japanese and international recruiting channels. For developers and teams in Europe, extra caution is still needed with unsolicited interview requests, test files, and software that comes from outside their own environment. A previous infiltration at MetaMask also showed how far North Korean actors can get by posing as legitimate developers or contractors.