North Korean Hackers Stole $10.71 Million in Crypto
A multinational advisory revealed a hacking group targeted over 7,000 wallets using AI and sophisticated malware.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you still trust the legitimacy of remote technical job interviews you encounter online?
Between December 2025 and July 2026, the North Korean hacking group WaterPlum infected more than 30,000 devices across over 100 countries. The group successfully stole approximately $10.71 million from more than 7,000 cryptocurrency wallets.
Why it matters
The hackers specifically target professionals in the crypto, AI, and NFT sectors to infiltrate devices and drain assets. By using AI face-swapping software during fake job interviews, the group maintains a sophisticated front to deploy malware.
WaterPlum infected 30,000 devices using malware families including BeaverTail, InvisibleFerret, and OtterCookie. The hackers leverage AI face-swapping technology during live video calls to pose as recruiters.
The players
WaterPlum
This is a North Korean hacking group that previously operated under the name Contagious Interview.
The details
Operators impersonate recruiters on professional platforms to trick candidates into downloading malicious files under the guise of an interview process. This group, formerly known as Contagious Interview, shares personnel and tactics with broader North Korean remote-IT-worker fraud schemes.
Timeline
The group WaterPlum began operating in 2023.
Malware infections and crypto theft occurred from December 2025 through July 2026.
A joint advisory from five nations was published on September 18, 2026.
The Tech Race
This activity marks an evolution of North Korea's remote-IT-worker fraud scheme by integrating AI-driven deceptive techniques. The group has moved beyond traditional social engineering to adopt advanced face-swapping software, signaling a shift in how threat actors exploit remote work infrastructure.
Users in the tech, crypto, and AI industries should exercise extreme caution during remote job interviews with unknown recruiters. Always verify the identity of interviewers and avoid downloading unsolicited software or files during the hiring process.
The takeaway
The sophisticated nature of these attacks highlights how professional platforms can be manipulated for large-scale financial theft. Individuals should remain vigilant by confirming recruitment offers through official company channels and keeping security software updated.
Further reading
For more on the current threat landscape, visit the Cybersecurity section.
Source note: This article includes information reported by Startup Fortune.
Live Poll
Do you still trust the legitimacy of remote technical job interviews you encounter online?







