A joint advisory on September 18, 2026, links a North Korea–connected group called WaterPlum to a global campaign that compromised over 30,000 devices and stole about $10.71 million in cryptocurrency. Attackers posed as recruiters and delivered weaponized coding tests that installed malware to exfiltrate wallet keys, keystrokes and identity documents. Authorities warn never to run third‑party code on machines that hold wallet keys, and they recommend using Restricted Mode, sandboxes or isolated VMs and treating suspected compromises as confirmed.
Fake Coding Tests Linked to North Korea Stole $10.71M in Crypto — 30,000+ Devices Infected

A software developer responding to a seemingly legitimate LinkedIn recruiter was asked to complete a coding test hosted on GitHub. After cloning and running the repository, the developer’s machine was infected within minutes by a keylogger that captured every keystroke — including the passphrase to a cryptocurrency wallet.
That scenario is central to a joint advisory published on September 18, 2026. Authorities say a North Korea–linked group known as WaterPlum compromised more than 30,000 devices across over 100 countries and stole approximately $10.71 million in cryptocurrency. The alert was coordinated by Japan’s National Police Agency, the U.S. FBI, Australia’s ASD Cyber Security Centre, and Germany’s BND and BfV.
How the Scam Worked
WaterPlum actors impersonated recruiters on job platforms and social media, targeting software engineers, web designers and Web3 professionals with remote roles at AI, crypto and NFT firms. After initial contact, victims received a "technical assignment" — often a Git repository or an NPM package — supposedly to test skills or fix a video-call problem.
When targets ran the provided code, it deployed malware families named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. These tools quietly exfiltrated credentials, clipboard contents, keystrokes, cryptocurrency wallet data and identity documents, and they often maintained persistent access long after the interview ended.
Scale, Impact and Strategic Use
Between roughly December 2025 and July 2026, investigators say WaterPlum drained or captured credentials from more than 7,000 cryptocurrency wallets, transferring a total of about 1.7 billion yen (≈ $10.71 million) to North Korea. The roughly 30,000 infected devices across 100+ countries show this was a global campaign, not a localized incident.
Researchers link the campaign to a broader North Korean IT worker ecosystem. Estimates suggest about 100,000 IT workers operating under false identities worldwide could generate hundreds of millions of dollars annually — revenues that help the regime evade sanctions. Stolen credentials and identity documents also support long-term evasion and illicit finance operations.
Practical Advice For Employers and Candidates
The advisory includes specific red flags for hiring managers: applicants who refuse on-camera verification, show video anomalies consistent with AI face-swapping, underperform drastically compared with their resume, or insist on payment exclusively in cryptocurrency. These behaviors should be treated as serious warning signs.
For developers and crypto users, the summarized guidance in the Gblock security briefing is blunt:
"Never execute third-party code on a machine that touches your wallets or personal data."Practical steps include opening unknown Visual Studio Code projects in Restricted Mode, rejecting "trust" prompts for unfamiliar directories, and running recruiter-sent code in sandboxed environments or virtual machines that are isolated from wallet keys and personal accounts.
If You Suspect a Compromise
The advisory recommends treating suspected compromise as confirmed: assume passwords, credentials and sensitive files were exposed. Immediately isolate the affected systems, rotate passwords and keys from a known-clean device, initiate a full forensic investigation and coordinate with national cybersecurity authorities. Rapid response reduces long-term damage and aids law enforcement tracing.
Wider Implication
This campaign makes clear that remote hiring practices and trust in shared code repositories are now a documented attack surface. Hiring platforms, developer tools and identity-verification processes must adapt to close this vector and protect candidates and employers alike.
Key sources: Joint advisory (Sept 18, 2026) from Japan NPA, FBI, Australia ASD Cyber Security Centre, Germany BND/BfV; Gblock security briefing.
Help us improve.



























