Hackers linked to North Korea have infected tens of thousands of job seekers’ devices across more than 100 countries in order to steal data and cryptocurrency, international agencies have warned.
The WaterPlum group, also known as Contagious Interview, targets software developers and IT professionals by posing as prospective employers with fake “dream job” offers, according to the Federal Bureau of Investigation (FBI).
A joint cyber security advisory issued by Australian, German, Japanese and US authorities stated that the hacks occurred between December 2025 and July 2026, though the FBI warned that the threat is still active.
“WaterPlum is targeting IT professionals in Japan, the United States, Europe, and beyond,” the US federal agency said.
The hackers have already stolen funds or account credentials from over 7,000 crypto wallets, transferring $10.8 million (£8.1 million) worth of assets to the Democratic People’s Republic of Korea.
The FBI and Japan’s National Police Agency (NPA) claim to have identified “enablers” in the US and Japan that facilitate the operation.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the advisory noted.
“They often impersonate legitimate artificial intelligence (AI), cryptocurrency, or non-fungible token (NFT) companies and have also used recruiting services.”
The group targets potential victims through social media and online job platforms, requiring any applicants to complete virtual interviews or complete technical assignments.
During the interview, WaterPlum hackers instruct the job seekers to download and execute malicious files which give them backdoor access to the victim’s computer networks.
The agencies warned IT workers to be vigilant about being approached by third parties offering job opportunities.
“If you suspect that a business partner or contractor may be a North Korean IT worker, contact the police immediately,” the advisory stated.
“Depending on individual circumstances, knowingly providing payment or personal ID images to North Korean actors could constitute a crime.”