A fake job interview was all it took to turn thousands of computers into hunting grounds for passwords, screenshots, keystrokes and crypto wallets.
A North Korea-backed hacking group known as WaterPlum infected more than 30,000 devices across over 100 countries, according to a joint advisory from Japan’s National Police Agency and the FBI. The operation also compromised data from more than 7,000 crypto wallets.
Between December 2025 and July 2026, wallets controlled by the group received at least $10.71 million in digital assets.
The campaign, which investigators also track as Contagious Interview, targeted a particularly useful corner of the internet: developers and IT professionals who spend their days downloading code, testing software and taking calls from strangers who claim to be hiring.
How fake recruiters found crypto wallets
WaterPlum posed as a recruiter for companies in artificial intelligence, cryptocurrency and non-fungible tokens. Its targets were approached through social media, job boards and freelance platforms, often with the familiar promise of an attractive technical role.
The setup was designed to look routine. Candidates were asked to complete a coding challenge or take part in a technical interview. Then came the file download.
Sometimes the excuse was a broken video call. Other times, the malicious software was presented as part of the coding assignment itself.
Once installed, the malware could search through a victim’s machine for browser passwords, screenshots and keystrokes. It could also go after the secret keys used to control crypto wallets, turning an ordinary laptop into a direct route to digital assets.
That makes the campaign particularly effective. The victims did not necessarily need to be singled out because of how much cryptocurrency they owned. They only needed to be willing to run software from someone claiming to offer them a job.
The scale revealed by authorities is also striking. In August, BeInCrypto reported on a researcher who had spent 22 months inside the group’s servers and identified 1,640 victims across 57 countries. The official figure announced Friday is roughly 18 times larger.
Crypto wallets were only part of the operation
The investigation also uncovered a separate piece of the alleged infrastructure in Japan.
Police dismantled what authorities described as the country’s first known laptop farm, where local helpers kept computers inside their homes while North Korean workers operating abroad controlled them remotely.
The workers allegedly used the setup to impersonate Japanese residents while pursuing freelance contracts. Investigators said those workers transferred several hundred million yen worth of cryptocurrency overseas, and internet addresses associated with the operation were also connected to the hackers.
The Japanese and US authorities said, “The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.”
The recruitment tactics appear to have evolved alongside the operation. Earlier campaigns reportedly used deepfake video calls to target senior employees, adding a layer of synthetic credibility to the impersonation.
One suspected North Korean operative even applied for an engineering position at Japanese crypto exchange bitFlyer in May 2025 using a stolen résumé.
The application raised several red flags. The candidate refused to relocate, requested payment in cryptocurrency and appeared to be reading responses from another screen. He was not hired.
For engineers and developers, authorities now recommend treating recruiter-provided code with the same caution as any other untrusted software. Investigators specifically advised running such programs inside a sandbox, an isolated environment separated from the computer’s real files and credentials.
In a campaign built around convincing people that they are being evaluated for a career opportunity, the most valuable thing on the other side of the interview may not be a résumé at all. It may be the keys sitting quietly inside the candidate’s computer.
