A sophisticated state-linked cyberattack has quietly carved a path through the global technology workforce, infecting at least 30,000 devices across more than 100 countries and siphoning at least $10.71 million in cryptocurrency — not through brute-force exploits, but through something far more insidious: a fake job offer. The campaign, formally tracked as WaterPlum and widely known in threat intelligence circles as Contagious Interview, has been attributed to North Korea-linked threat actors and represents one of the most geographically expansive crypto-targeting operations documented to date.

A Recruitment Ruse Built for the Digital Economy

The attack's methodology is as elegant as it is alarming. Threat actors posed as legitimate employers, crafting convincing recruitment pitches aimed squarely at developers and information technology professionals — precisely the demographic most likely to hold or manage cryptocurrency assets and to interact with development environments capable of executing arbitrary code. Victims were lured through fake interview processes, likely delivered via professional networking platforms and messaging channels, before being prompted to run malicious packages or install compromised software under the guise of a technical assessment or onboarding task.

This social engineering approach is not new to North Korea's hacking playbook, but WaterPlum's scale makes it stand apart. The operation succeeded in compromising credentials or funds from over 7,000 cryptocurrency wallets — a number that underscores how effectively the campaign targeted individuals with direct access to digital assets rather than simply casting a wide net against corporate infrastructure. Stolen funds totaled at least 1.7 billion Japanese yen, a figure that converts to approximately $10.71 million at current exchange rates.

Scale and Reach Signal Institutional-Grade Threat

The geographic breadth of WaterPlum — spanning more than 100 countries — signals a level of operational coordination that goes well beyond opportunistic cybercrime. Running a campaign of this scope across diverse jurisdictions, languages, and professional communities requires infrastructure, patience, and intelligence gathering. This is the hallmark of a state-sponsored actor optimizing for revenue generation under international sanctions, not a freelance criminal group chasing quick returns.

North Korea has long used cryptocurrency theft as a mechanism to circumvent the financial isolation imposed by the United States, the United Nations, and other jurisdictions. Prior campaigns attributed to Pyongyang-linked groups — including the Lazarus Group and its various sub-clusters — have collectively accounted for billions of dollars in crypto losses over the past decade. WaterPlum appears to be operating within that same strategic framework: target professionals with technical access, harvest credentials at scale, and convert stolen assets into fungible value that bypasses the traditional banking system.

Developers Are the New Attack Surface

What makes Contagious Interview — the operational alias under which WaterPlum has been tracked by multiple threat intelligence teams — particularly notable is its deliberate targeting of software developers and IT professionals. These individuals represent a uniquely vulnerable and uniquely valuable cohort. They routinely install packages from external repositories, run code in local environments, and interact with blockchain-adjacent tooling. A developer who believes they are completing a legitimate coding assessment is far less likely to scrutinize the packages they are asked to install than a general employee receiving a phishing email.

The attack surface here is the developer workflow itself. Malicious npm packages, GitHub repositories seeded with backdoored code, and trojanized coding challenge repositories have all been documented as delivery mechanisms in campaigns bearing WaterPlum's fingerprints. Once an initial foothold is established on a developer's machine, operators can move laterally, harvest stored credentials, extract browser-based wallet data, and exfiltrate private keys — all before the victim realizes anything has gone wrong. The result: 30,000 compromised machines and more than 7,000 cryptocurrency wallets drained or exposed.

What This Means for the Crypto Industry

The WaterPlum campaign delivers a sharp reminder that the industry's largest security vulnerabilities are increasingly human rather than purely technical. Multi-million-dollar protocol exploits and bridge hacks dominate headlines, but operations like Contagious Interview illustrate that nation-state actors are just as willing — perhaps more willing — to exploit trust and professional ambition as they are to probe smart contract code for bugs.

For crypto-native companies, decentralized finance (DeFi) teams, and blockchain infrastructure providers, the implications are direct. Hiring pipelines, contractor onboarding flows, and technical assessments all represent potential insertion points for adversaries operating with state-level patience and resources. The 7,000-wallet compromise figure also raises questions about the adequacy of current operational security practices among individual holders and developers who manage significant on-chain assets without the institutional custody guardrails that protect enterprise-grade portfolios.

Regulatory bodies and cybersecurity agencies that have repeatedly warned about North Korea's crypto-theft apparatus will likely cite WaterPlum as further evidence that the threat is evolving in sophistication and reach. For the developers, engineers, and IT professionals who form the backbone of the digital asset industry, the $10.71 million taken by WaterPlum is less a headline number than a calibration point: the cost of underestimating a fake job offer.

Written by the editorial team — independent journalism powered by Bitcoin News.