Fake Recruiters Infected 30,000 PCs in a $10.7M Crypto Theft
Want more insights like this?
The FBI's Cyber Division, with Japanese, Australian, and German authorities, warned on September 18 that a North Korea-linked group tracked as WaterPlum — also called Contagious Interview — infected more than 30,000 personal computers across 100-plus countries between December 2025 and July 2026. Posing as recruiters on job boards, social networks, and freelance platforms, they got developers to run malicious files as fake coding tasks.
Some used AI face-swapping software to appear as the recruiter on video calls, then cut the camera a few minutes in, blaming network trouble. The payloads include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which between them steal credentials, wallet keys, and project files. Authorities put the haul at 7,000 cryptocurrency wallets and $10.71 million moved to North Korea.
A compromised developer is also a route into their employer's network, which is what lifts this above an individual problem. Run code from a recruiter only in a sandbox or virtual machine, never on a machine holding personal data or wallets. If you find an infection, disconnect immediately and assume the data is already gone.
Source: Cyber Security News