The North Korean hacking group WaterPlum, also known as Contagious Interview, has been identified as a significant threat, infecting at least 30,000 devices across over 100 countries and compromising over 7,000 cryptocurrency wallets.According to reporting by Infosecurity Magazine, the malicious activity, which ran from December 2025 to July 2026, resulted in approximately $10.7 million in cryptocurrency being transferred to North Korea. Joint advisories from Japan's National Police Agency, the FBI, and other international cybersecurity agencies revealed that WaterPlum actors impersonated employers, particularly AI and cryptocurrency firms, to recruit developers. Victims were tricked into downloading malicious files disguised as coding assignments, which contained malware such as BeaverTail and StoatWaffle. Once installed, the malware stole credentials, wallet private keys, and personal identification documents, with infections sometimes providing access to victims' employers. The operation is closely linked to North Korea's IT worker scheme, with some actors operating from laptop farms and utilizing shared infrastructure. Japanese authorities have dismantled a laptop farm in Japan as part of their investigations into this scheme.Source: Infosecurity Magazine