Skip to content

Invest1 publisher2 min readPublished

Four governments pin $10.7m of crypto theft on fake recruiter coding tests

A joint advisory ties about $10.71 million of stolen cryptocurrency to more than 30,000 infected devices in over 100 countries. That works out near $357 a machine, and the payroll half of the same operation ran for years.

The Investor · Invest desk

Illustration accompanying Four governments pin $10.7m of crypto theft on fake recruiter coding tests

What happened

  • Seven agencies from four countries published a joint advisory on 18 September 2026 naming WaterPlum, which also operates as Contagious Interview, as the North Korean crew that posed as tech recruiters.
  • The signatories are Japan's National Cybersecurity Office and National Police Agency, the FBI, the US Department of Defense Cyber Crime Center, Australia's ASD Cyber Security Centre, and Germany's BND and BfV.
  • The agencies said the group diverted 1.7 billion yen, about $10.71 million, of cryptocurrency to North Korea.
  • Between December last year and July this year the operation infected more than 30,000 devices across more than 100 countries and took data belonging to about 7,000 cryptocurrency accounts.
  • Japanese authorities spotted, investigated and stopped a laptop farm run by a local enabler who fronted the hackers' work, the first case of its kind in Japan.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure The infection happened on the applicant's own machine during an interview task, so a hiring funnel is reachable without any corporate asset being touched.
  • cost Individual holders absorbed the loss at roughly $1,530 per compromised crypto account, not an exchange balance sheet.
  • decision One advisory hands hiring managers two screening problems: the applicant who infects the laptop, and the remote contractor whose salary is routed to Pyongyang.
  • precedent With seven agencies willing to co-sign a named group under a public attribution framework, the next campaign in this family can expect to be named publicly too.

Divide the $10.71 million the seven agencies traced by the 30,000-plus devices they counted, and the campaign returned about $357 a machine [3][4][1]. Under a quarter of the machines gave up wallet credentials at all: 7,000 compromised crypto accounts against a 30,000-device infection count is roughly 23 percent [4][2]. Eight months, more than 100 countries, about $1.34 million a month [3][4][4].

Set that beside the roughly $6.75 billion the G7 said in June had been stolen since 2016 by actors with North Korean links, and the advisory's total is about 0.16 percent of it [12][3][3]. The G7 count runs from 2016; the WaterPlum window runs from December to July [12][4].

The other half of the operation is a payroll. Japan's National Police Agency says North Korean IT workers living in North Korea, China and Russia won remote programming and web-development contracts under cover [10]. Their pay went home, hundreds of millions of yen over the years, a figure given without a year-by-year split [10]. At the conversion the agencies used, about 159 yen to the dollar, 300 million yen is near $1.9 million [3][5].

For a company that hires developers, the exposed step is the assignment itself. The payload sat in Node Package Manager packages: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle [6]. Once running, the code opened a backdoor, held access with remote-access trojans and pulled browser passwords, keystrokes, screenshots, wallet private keys and seed phrases [6]. Black Hat researcher Vangelis Stykas said this year that he had traced North Korean hackers into 1,640 companies across 57 countries, often by baiting developers with fake job offers that install malware [13].

The NPA and the FBI assess that WaterPlum and the IT workers answer to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers' Party of Korea [7]. North Korea denies that its crypto thefts fund weapons [8].

I think the contracting income is the steadier of the two lines: salaries recur, and the wallet drain has an end date in the advisory [10][4]. The counter is straightforward. Credentials from 7,000 accounts keep their value after the window closes, and the agencies counted what they could trace, so $10.71 million is a floor on what that infection set eventually costs [4][3]. If a revised figure for December to July comes in several times higher, the developer lure is the bigger business and I have the weighting wrong.

What to watch

  • Any revision by the seven agencies to the $10.71 million figure for the December-to-July window.
  • Whether Japan's NPA publishes a year-by-year figure for salaries routed home by North Korean IT workers.
  • Whether other governments co-sign the WaterPlum attribution or attach sanctions to the 313 General Bureau.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories