Four governments attribute crypto theft campaign to North Korea-linked WaterPlum
A joint advisory says fake technical interviews infected at least 30,000 computers in more than 100 countries and exposed cryptocurrency wallets and workplace data.
Japan, the United States, Australia and Germany publicly attributed a cyber campaign to the North Korea-linked group WaterPlum, also known as Contagious Interview, in an advisory published Sept. 18. The Australian Cyber Security Centre notice says the operation targeted job seekers and IT professionals by using fraudulent recruiting approaches to gain access to computers, credentials and cryptocurrency wallets.
The agencies say WaterPlum compromised at least 30,000 computers across more than 100 countries between December 2025 and July 2026. The number describes infections identified by the authorities, not a complete count of every machine the group may have reached. The advisory also says the stolen data can support theft from victims, their employers or clients.
This is a government attribution, not a court finding. North Korea has routinely rejected accusations tied to cyber operations, and the public notice does not identify every victim or quantify every digital-asset loss.
Fake interviews became the delivery channel
The campaign’s lure starts with a plausible professional interaction. Investigators describe fake job offers, coding tests and requests to run software or share project files. The tools can capture keystrokes, browser data, identity documents, clipboard contents and wallet information after a victim installs the package or opens a malicious project. Interview code is untrusted code.
The agencies also warn that operators may use artificial-intelligence face-swapping during video calls, then ask a candidate to disable a camera. That detail matters because a polished interview does not prove the recruiter or the code is legitimate. A real company, a real vacancy and a real-looking technical task can still be part of the attack chain.
The public advisory links the activity to cryptocurrency theft, but it also describes espionage and intellectual-property collection. Crypto professionals face extra exposure because browser extensions, seed backups and exchange credentials may sit on the same machine used for development work.
What the advisory changes for crypto teams
The joint statement gives security teams a concrete reason to tighten hiring and contractor workflows. Applicants should not run unreviewed code during an interview, and companies should separate recruitment devices from wallets, signing systems and production credentials. Developers can also inspect package provenance, use isolated environments and rotate secrets after an unexplained install.
The scale claim still needs to be read carefully. The notice says at least 30,000 devices and references thousands of cryptocurrency wallets in supporting material, but public attribution does not reveal the full value stolen from each victim or prove that every infected computer held crypto. Those gaps matter when estimating losses or choosing controls.
The practical lesson is simple: treat an interview artifact like untrusted software. Recruiters can be part of the threat model. People managing digital assets should review wallet permissions, revoke exposed credentials and seek incident-response help after a suspected compromise; this article is not a recovery or investment instruction.