An international coalition of seven cybersecurity and intelligence agencies, including the FBI and the Japanese police, recently issued a major alert regarding the activities of the North Korean hacker group known as WaterPlum. This collective, also referred to as "Contagious Interview," is orchestrating a sophisticated cybercrime campaign primarily targeting developers working in the artificial intelligence and blockchain sectors. In less than a year, between December 2025 and July 2026, these hackers successfully infected over 30,000 devices across a hundred countries, causing an estimated $10.71 million in losses.
The modus operandi relies on well-honed social engineering: hackers pose as credible recruiters to lure freelance engineers into booby-trapped technical tests. During these assessments, victims are encouraged to install software packages containing concealed malware. Once executed, these malicious programs, such as BeaverTail or InvisibleFerret, act as backdoors, instantly siphoning credentials, private keys, and the entire contents of the developers' digital wallets.
The investigation has revealed concerning structural aspects, notably the deployment of "computer farms" in Japan, where local intermediaries host and remotely operate machines used by North Korean agents. These operations, closely linked to the 313th General Bureau of the Workers' Party of Korea, serve a dual purpose: financing the regime through the theft of digital currencies and industrial espionage. Authorities further underscore the quasi-industrial nature of these attacks, while noting, with a hint of irony, that the group's members pause their malicious activities during their country's official holidays.
Faced with this persistent threat, security agencies are now prioritizing a doctrine of public attribution, aiming to explicitly name the perpetrators of attacks to foster global awareness. This defense strategy requires increased vigilance from recruiters and tech companies, who are urged to drastically strengthen their verification protocols. Despite this exposure, experts agree that the resilience of digital infrastructure depends on a profound shift in security practices during technical hiring processes, in a crypto ecosystem where the slightest vulnerability can lead to irreversible financial consequences.