Fake Job Interviews: How North Korean Hackers Infiltrated Global Crypto Wallets
A joint cybersecurity advisory issued by the FBI, Japan's National Police Agency, and other international law enforcement bodies has detailed a widespread malware campaign linked to North Korean state-sponsored hackers, known as WaterPlum or Contagious Interview.
The Sophisticated Recruitment Ruse
Moving beyond generic phishing emails, the attackers executed a highly targeted social engineering scheme. They created convincing fake profiles posing as recruiters for companies in artificial intelligence, cryptocurrency, and non-fungible token (NFT) sectors on professional networking and job platforms.
After engaging with potential victims—often software developers and IT professionals—the hackers would schedule a technical interview. As part of the "screening process," candidates were instructed to download and run a coding test or assessment tool, which was actually malicious software designed to infiltrate their systems.
- The Bait: Lucrative job offers for roles like AI engineer, blockchain developer, or smart contract auditor.
- The Channel: Legitimate professional networks and job boards.
- The Hook: A mandatory "technical assessment" involving a downloadable file.
Global Reach and Significant Financial Loss
The campaign, active from December 2025 through July 2026, successfully compromised more than 30,000 devices across over 100 countries and regions.
Once installed, the malware stealthily scanned infected computers for cryptocurrency wallet data, including seed phrases and private keys. To date, information from more than 7,000 digital wallets has been stolen. Blockchain analysis shows that at least $10.71 million has been siphoned into wallets controlled by the attackers.
Protecting Yourself from Job Scam Malware
For professionals in the tech and crypto space, vigilance during the job hunt is critical:
- Be skeptical of interview requests from unverified companies, especially those requiring downloads of unusual tools or executables.
- Prefer official communication channels and video calls for interviews. Treat offline "coding test packages" with extreme caution.
- Use hardware wallets for significant crypto holdings, keeping private keys physically separated from internet-connected devices.
- Keep security software updated and analyze suspicious files in a sandboxed environment if possible.
This campaign underscores the evolving sophistication of cyber threats, where attackers expertly exploit human psychology and professional ambitions. Securing digital assets demands constant awareness in today's interconnected landscape.