> International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
[AUTHOR: Tim Starks]
[DATE: 18/09/2026 15:48]
[LANGUAGE: EN]
North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.
The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”
Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.
They’ve used the stolen information to fuel other operations, and the overlap between WaterPlum and North Korean IT workers is substantial, the agencies said.
“WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange,” they wrote.
Collectively, WaterPlum has infected more than 30,000 devices in more than 100 countries, targeting IT professionals in Japan, the United States, Europe and other nations. Its operations have transferred the equivalent of nearly $11 million of cryptocurrency from over 7,000 crypto wallets to North Korea, according to the alert.
The law enforcement agencies said they have had some success tackling the group, but are seeking further cooperation and released details in the alert about WaterPlum’s tactics, techniques and procedures.
“For the first time in Japan, authorities successfully identified, investigated, and dismantled a ‘laptop farm’ operated by an enabler in Japan,” the alert reads. “Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan. The FBI continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers.”
The warning comes as the Multilateral Sanctions Monitoring Team, an international panel overseeing UN sanctions against North Korea, released a report exposing thousands of North Korean nationals employed in industries around the world.
The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.