Hacking Group Stole $10.71 Million From Crypto Wallets
A state-linked North Korean group compromised 7,000 wallets by leveraging AI face-swapping in fake remote-work interviews.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you still trust the legitimacy of remote technical job interviews you encounter online?
Between December 2025 and July 2026, the North Korean hacking group WaterPlum infected over 30,000 devices across 100 countries to steal $10.71 million. A joint international advisory released in September 2026 detailed these findings, confirming the group's transition from previous operations known as Contagious Interview.
Why it matters
This campaign demonstrates the evolving sophistication of remote-work fraud, where attackers leverage AI-assisted video impersonation to bypass standard security screening. By specifically targeting professionals in high-value technical sectors, these actors gained persistent access to both internal company systems and private financial assets.
The attackers utilized AI face-swapping software to deceive job candidates and recruiters during live video calls, eventually distributing malware families identified as BeaverTail, InvisibleFerret, and OtterCookie.
The players
WaterPlum
A North Korean state-linked hacking group formerly known as Contagious Interview that utilizes AI-driven social engineering for financial theft.
The details
Operators impersonating recruiters on professional platforms conduct simulated interviews to entice victims into executing malicious payloads. Once installed, these malware families act as trojans to exfiltrate session data and credentials from cryptocurrency wallets. The group shares operational ties with established North Korean remote-IT-worker fraud schemes, indicating a consolidated approach to generating illicit revenue through technical impersonation.
Timeline
WaterPlum began its operations in 2023.
The campaign infected 30,000 devices between December 2025 and July 2026.
A five-nation joint advisory was published on September 18, 2026.
The Tech Race
This campaign marks a transition from simple wage-theft operations to high-volume automated malware distribution against technical professionals. It signals a move toward weaponizing AI-driven video deception to bypass the trust-based screening processes commonly used in remote-first tech hiring.
Technical workers and crypto-asset holders should increase scrutiny of remote job interview processes, particularly when a platform request includes downloading third-party software or executables. Organizations remain at risk of persistent device compromise if screening tools do not authenticate video interview identity signals.
The takeaway
The use of AI-driven impersonation in professional hiring represents a new frontier in identity-based social engineering. Security professionals should monitor for future updates to the BeaverTail and InvisibleFerret malware signatures described in the September 2026 international advisory.
Further reading
For more context on current threats and defensive strategies, see our coverage of Cybersecurity.
Source note: This article includes information reported by Startup Fortune.
Live Poll
Do you still trust the legitimacy of remote technical job interviews you encounter online?






