The joint advisory says a North Korean-linked crew posing as recruiters stole funds or credentials from more than 7,000 crypto wallets, moving about $10.71 million to Pyongyang. The group, known as WaterPlum or Contagious Interview, infected at least 30,000 devices across 100+ countries between December 2025 and July 2026 and delivered multiple malware families via fake technical interview downloads. Agencies link the campaign to North Korea's 313 General Bureau and warn developers to watch for common red flags and avoid executing unsolicited files.
North Korean 'Recruiter' Scam Drains $10.71M From 7,000+ Crypto Wallets in Global Campaign

A North Korean-linked crew posing as recruiters targeted developers and drained funds or stole credentials from more than 7,000 cryptocurrency wallets, moving roughly $10.71 million to Pyongyang, according to a joint advisory published on September 18 by seven agencies across four countries.
What Happened
The group—called WaterPlum by Japan's National Police Agency and Contagious Interview in the security sector—infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026. Their targets included web designers, software engineers and specialists working in crypto, blockchain and Web3 development.
How The Scam Worked
Operators impersonated AI, crypto and NFT firms and contacted candidates via social media, job boards and freelance marketplaces to schedule technical interviews or coding tests. During video calls they asked candidates to download files from developer platforms to complete assignments or to "fix" an apparent call problem. Those downloads delivered malware; investigators identified five families used in the campaign, including BeaverTail, InvisibleFerret and StoatWaffle (the latter hidden in blockchain-themed code repositories).
Tradecraft And Attribution
Investigators observed the crew using AI face-swap tools in interviews, then cutting the feed and asking candidates to do the same while blaming the connection. Members practised Japanese pronunciation with text-to-speech, relied heavily on free machine translation and free AI tiers, and reportedly paused operations on North Korean holidays. The NPA and FBI assess the operation is linked to North Korea's 313 General Bureau of the Munitions Industry Department; shared IP addresses used to access laptop farms, crowdsourcing services and job portals helped tie the activity together.
Domestic Enabler And Wider Context
Japanese authorities uncovered and dismantled a laptop farm run by a domestic enabler—the first such case identified in Japan—and found evidence that several hundred million yen in cryptocurrency had been moved overseas. Security firm CertiK attributed about $2.06 billion (roughly 60%) of crypto thefts in 2025 to North Korea-linked groups. The advisory also recalled April's $285 million Drift Protocol hack, which followed a pattern of attackers posing as a quantitative trading firm.
Red Flags And Practical Advice
Common warning signs included implausibly broad résumés, language mismatches, refusal to meet in person, requests for payment in cryptocurrency, and repeated glances at a second screen during video calls. To reduce risk: keep development tools and antivirus software updated; never run unsolicited downloads or code in your working environment; verify recruiters and job postings through independent channels; use hardware wallets or multi-factor authentication for crypto holdings; and treat unexpected interview requests that require file execution with deep suspicion.
Help us improve.



























