Skip to content

Invest1 publisher2 min readPublished

North Korea's fake recruiters cleared about $357 per infected device

Japan, Germany, Australia and the US say one North Korean group infected 30,000 devices in more than 100 countries to steal $10.7 million, a thin cash yield that points at the identity documents it also took.

The Investor · Invest desk

What happened

  • A joint advisory from Japan, Germany, Australia and the US says the North Korean group WaterPlum, also called Contagious Interview, stole at least $10.7 million by posing as recruiters for real crypto and AI companies.
  • The group infected at least 30,000 devices in more than 100 countries, and funds or account credentials were pulled from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
  • Lures ran through social media, online job platforms, gig work platforms and freelance marketplaces, with malicious files handed to candidates as coding assignments or fixes for video-conferencing errors.
  • The advisory ties WaterPlum to North Korea's wider campaign of placing IT workers inside foreign companies, attributing the malware operation and the worker-placement operation to the same North Korean effort.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure A company's exposure now sits on a contractor's personal laptop, arriving through a job application the company never saw and cannot audit.
  • capability Each harvested passport scan and resume gives North Korea's IT-worker operation a fresh identity to apply under, so one infection can be resold as a hire.
  • constraint Talent and engineering teams cannot filter the inbound side of this, because the malicious step happens on the candidate's machine before any employer relationship exists.
  • contradiction The advisory quantifies devices, wallets and dollars. The infiltration it warns about is illustrated only by attempts that were caught.

Divide $10.7 million by 30,000 devices and the take is about $357 a machine [1]. Measured against the 7,000-plus wallets that gave up funds or account credentials, it is roughly $1,529 each [2], or about 875 wallets a month across the eight-month window [5]. Set that beside the $1.5 billion Bybit theft, which the FBI blamed on North Korea in February 2025 [14]; the recruiting campaign produced about 0.7 percent of it [3].

Only about 23 percent of the infected devices yielded a wallet extraction at all [4]. The rest handed over whatever the remote-access trojans and infostealers found on a developer's machine [7]. The advisory is explicit about the value of that material: stolen identity documents let North Korean IT workers impersonate victims and earn income, and sensitive information can support extortion [9]. A successful infection also opens a path into whoever employs the developer [8].

"The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies," the four governments said [5]. The unit of attack is one freelancer, and the operators impersonated real AI, crypto and NFT firms and used recruiting services to reach them [16].

On the employer side, the advisory's own examples are of attempts that were caught. It describes a suspected North Korean IT worker who applied for an engineering role at a Japanese crypto exchange on a forged resume. The applicant was rejected after the interview turned up discrepancies, including an inability to explain the listed skills in detail [12]. In July, Consensys told Cointelegraph it had unknowingly engaged a North Korea-linked developer as a consultant and terminated the access after discovering the threat. The company said its investigation found no theft of assets or data, no malicious code deployment and no impact on user safety [13].

The $10.7 million is a floor, since the advisory says at least that much [2], so a per-device figure computed from it understates the real take by however much went untraced. If a later accounting triples the number, then this was a theft operation with a recruiting front and the identity harvest is the sideline. I'd take the other side of that. US authorities have warned about undercover IT workers since at least 2018 [15]. Japanese and US authorities assess that WaterPlum actors and some of those workers operate under North Korea's Munitions Industry Department [10]. A placed worker draws a salary for as long as the cover holds. The malware paid $357 a device [1].

What would overturn it is a disclosed case in which an employer of an infected contractor reports a loss with a number attached.

What to watch

  • A revised attribution above $10.7 million in any follow-up advisory would change the per-device economics this piece rests on.
  • A disclosed loss at a company that employed an infected contractor.
  • Any removal or takedown data from the gig and freelance platforms named as lure channels.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories