Hacking Group Stole $10.71 Million From Crypto Wallets

A state-linked North Korean group compromised 7,000 wallets by leveraging AI face-swapping in fake remote-work interviews.

Updated on Oct. 3, 2026 in Cybersecurity

Isometric editorial illustration of a cold storage crypto wallet connected by a glowing cable to a large server base.
A state-linked North Korean hacking group successfully compromised 7,000 crypto wallets, stealing over $10.7 million by using AI-driven impersonation in fake job interviews. AI Illustration. Upload story photo >

Live Poll

Do you still trust the legitimacy of remote technical job interviews you encounter online?

Between December 2025 and July 2026, the North Korean hacking group WaterPlum infected over 30,000 devices across 100 countries to steal $10.71 million. A joint international advisory released in September 2026 detailed these findings, confirming the group's transition from previous operations known as Contagious Interview.

Why it matters

This campaign demonstrates the evolving sophistication of remote-work fraud, where attackers leverage AI-assisted video impersonation to bypass standard security screening. By specifically targeting professionals in high-value technical sectors, these actors gained persistent access to both internal company systems and private financial assets.

The attackers utilized AI face-swapping software to deceive job candidates and recruiters during live video calls, eventually distributing malware families identified as BeaverTail, InvisibleFerret, and OtterCookie.

The players

WaterPlum

A North Korean state-linked hacking group formerly known as Contagious Interview that utilizes AI-driven social engineering for financial theft.

The details

Operators impersonating recruiters on professional platforms conduct simulated interviews to entice victims into executing malicious payloads. Once installed, these malware families act as trojans to exfiltrate session data and credentials from cryptocurrency wallets. The group shares operational ties with established North Korean remote-IT-worker fraud schemes, indicating a consolidated approach to generating illicit revenue through technical impersonation.

Timeline

  1. WaterPlum began its operations in 2023.

  2. The campaign infected 30,000 devices between December 2025 and July 2026.

  3. A five-nation joint advisory was published on September 18, 2026.

The Tech Race

This campaign marks a transition from simple wage-theft operations to high-volume automated malware distribution against technical professionals. It signals a move toward weaponizing AI-driven video deception to bypass the trust-based screening processes commonly used in remote-first tech hiring.

Technical workers and crypto-asset holders should increase scrutiny of remote job interview processes, particularly when a platform request includes downloading third-party software or executables. Organizations remain at risk of persistent device compromise if screening tools do not authenticate video interview identity signals.

The takeaway

The use of AI-driven impersonation in professional hiring represents a new frontier in identity-based social engineering. Security professionals should monitor for future updates to the BeaverTail and InvisibleFerret malware signatures described in the September 2026 international advisory.

Further reading

For more context on current threats and defensive strategies, see our coverage of Cybersecurity.

Source note: This article includes information reported by Startup Fortune.

Live Poll

Do you still trust the legitimacy of remote technical job interviews you encounter online?