Four governments say North Korea's WaterPlum infected 30,000 devices through fake AI and crypto job interviews
A joint advisory from Japan, the US, Australia and Germany traces $10.7 million in stolen cryptocurrency and more than 7,000 drained wallets to the group between December 2025 and July 2026.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
A joint law enforcement advisory from Japanese, US, Australian and German authorities says the North Korean hacking group WaterPlum compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026, BleepingComputer reports. The advisory states the group exfiltrated funds or account credentials from more than 7,000 cryptocurrency wallets and transferred 1.7 billion Japanese yen, equivalent to about $10.71 million, in stolen cryptocurrency to North Korea. WaterPlum is linked to the multi-year campaign known as Contagious Interview, which has previously targeted job seekers with malicious npm packages. The attackers impersonate legitimate AI, cryptocurrency and NFT companies or approach targets through recruiting and freelance platforms. During fake interviews and coding tests, victims are told to download projects, troubleshoot supposed video-conferencing problems or run code that turns out to be malicious. The advisory places WaterPlum within a broader ecosystem of North Korean actors conducting financially motivated intrusions to generate revenue for the regime and fund its weapons programs. The campaign is relevant to the AI sector in particular because the lure relies on the credibility of AI startups as employers, and because developers who install packages during coding tests often hold credentials for company repositories and wallets. Job seekers and hiring teams should treat unsolicited technical tests that require running unfamiliar code as a red flag.
Sources
- BleepingComputerNorth Korean WaterPlum hackers infected 30,000 devices worldwide