# North Korean Fake-Job Scheme Sent $10.71 Million in Crypto to DPRK

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/23258
Published: 2026-09-23T12:22:04.000Z
Updated: 2026-09-23T12:22:04.000Z

A North Korean campaign using fake job interviews transferred at least $10.71 million in cryptocurrency to the Democratic People’s Republic of Korea after funds or credentials were exfiltrated from more than 7,000 wallets.

The WaterPlum group, also known as Contagious Interview, compromised at least 30,000 devices in more than 100 countries from about December 2025 through July 2026. The operation targeted web designers, engineers and specialists in cryptocurrency, blockchain and Web3 technology.

Attackers posed as recruiters or employers and directed candidates to download files or run code during interviews and coding assignments. The campaign used BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware, including malicious software hidden in blockchain-themed developer projects.

StoatWaffle was hidden in blockchain-themed developer projects.

Japan’s National Police Agency (NPA) and the FBI assessed that WaterPlum and some North Korean information-technology workers operated under the 313 General Bureau of the Munitions Industry Department, which reports to the Workers’ Party of Korea’s Central Committee.

Japanese authorities also dismantled a domestic laptop farm used by North Korean IT workers to control computers remotely. Unfamiliar code should be run in a sandbox or virtual machine, and unknown Visual Studio Code projects should be opened in restricted mode.
