BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

North Korean Hackers Exploit Fake Job Listings to Steal $10.7M in Cryptocurrency

Key Highlights Cybercriminals with ties to North Korea successfully compromised over 30,000 devices worldwide through fraudulent employment opportunities. More than 7,000 digital currency wal

AnonymousCryptoCompass newsroom
September 21, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

Key Highlights

  • Cybercriminals with ties to North Korea successfully compromised over 30,000 devices worldwide through fraudulent employment opportunities.
  • More than 7,000 digital currency wallets fell victim to the sophisticated attack.
  • A minimum of $10.7 million in cryptocurrency was siphoned off and funneled to North Korea.
  • The cybercrime operation, identified as WaterPlum, specifically targeted software engineers and IT professionals with fabricated positions at cryptocurrency, artificial intelligence, and NFT firms.
  • Targets were frequently tricked into executing malicious software masked as technical assessments or solutions for video conferencing issues.

A cybercriminal organization with connections to North Korea deployed fraudulent hiring campaigns to compromise over 30,000 computing devices and pilfer a minimum of $10.7 million in digital assets, as detailed in a collaborative international security alert.

The criminal enterprise, identified by security researchers as WaterPlum and Contagious Interview, concentrated their efforts on software development professionals and information technology specialists spanning more than 100 nations.

Law enforcement and cybersecurity agencies from the United States, Japan, Australia, and Germany reported that the threat actors masqueraded as human resources representatives offering employment at seemingly authentic cryptocurrency, blockchain, artificial intelligence, and NFT enterprises.

Approximately 7,000 digital currency wallets were successfully breached during the period spanning December 2025 through July 2026.

Malicious Software Distributed Through Fabricated Employment Opportunities

The WaterPlum operation contacted potential victims through various channels including social networking platforms, employment websites, freelance contractor marketplaces, and professional recruitment services.

The threat actors presented compelling job opportunities before shepherding candidates through an elaborate fake technical vetting process.

Targets were subsequently instructed to execute files or run programming code presented as legitimate coding challenges or technical assessments.

Alternatively, job applicants were informed they required specialized software installation to resolve fabricated difficulties with video communication platforms.

These files actually contained malicious code engineered to grant unauthorized system access to the attackers.

Security agencies documented multiple malware variants deployed throughout the campaign, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

Following successful installation, the malicious software possessed capabilities to harvest web browser authentication credentials, clipboard contents, screen captures, keystroke logs, and locally stored files.

Cryptocurrency private keys and wallet recovery phrases represented primary targets for data exfiltration.

Criminal Operation Drains $10.7 Million from Digital Wallets

Investigating authorities confirmed that WaterPlum successfully extracted funds or account access credentials from over 7,000 cryptocurrency storage wallets.

A documented minimum of $10.71 million in stolen digital currency was successfully transferred to North Korean-controlled accounts, per the official advisory.

The breaches potentially introduce broader cybersecurity vulnerabilities for organizations that employed victimized developers.

Following successful compromise of an employee’s workstation, harvested credentials may potentially provide unauthorized access to corporate networks, client information, or proprietary business data.

Personal identification documentation represented another collection priority.

Authorities indicated that stolen passport images and identity verification documents could enable North Korean IT operatives to assume victims’ identities when seeking overseas employment opportunities.

Compromised data additionally presents extortion possibilities.

Investigators noted that certain WaterPlum operatives employed artificial intelligence-powered facial manipulation technology during virtual interviews before disabling their cameras and citing technical difficulties.

North Korean IT Workforce Infiltration Efforts Persist

The security advisory connected WaterPlum operations to North Korea’s broader strategic initiative to embed IT personnel within international corporations.

American and Japanese intelligence agencies assess that WaterPlum participants and certain North Korean IT professionals function under an organizational unit affiliated with the nation’s military-industrial complex.

One individual suspected of being a North Korean IT operative recently submitted an application for a software engineering position at a Japanese cryptocurrency exchange platform utilizing falsified credentials.

The candidate was ultimately rejected after interviewers detected inconsistencies between the applicant’s documented experience and their demonstrated ability to articulate the claimed technical expertise.

ConsenSys additionally revealed in July that the organization had inadvertently contracted a North Korea-affiliated developer as a consulting resource.

The firm immediately revoked the individual’s system access following discovery of the connection and stated that a comprehensive investigation determined no asset misappropriation, data exfiltration, malicious code injection, or compromise to user security occurred.

Security authorities are recommending that job seekers refuse to execute code or download materials from unverified recruitment sources and immediately isolate potentially compromised devices from network connectivity.

The post North Korean Hackers Exploit Fake Job Listings to Steal $10.7M in Cryptocurrency appeared first on Blockonomi.