Executive Summary
North Korean threat actors operating under WaterPlum (aka Contagious Interview) have compromised over 30,000 devices across 100+ countries by posing as legitimate AI, cryptocurrency, and NFT company recruiters targeting software developers and IT professionals. The campaign, linked to North Korea's 313 General Bureau, uses fake job opportunities to deliver malware and establish persistent access for cryptocurrency theft and data exfiltration. The operation has successfully stolen approximately $11 million in cryptocurrency from over 7,000 wallets while maintaining extensive overlap with broader North Korean IT worker infiltration efforts.
This incident highlights the evolution of North Korean cyber operations beyond traditional state-sponsored espionage toward systematic financial crime integrated with legitimate IT workforce infiltration, representing a new paradigm where threat actors blend cybercriminal activities with long-term economic penetration strategies.
Why This Matters Now
The convergence of social engineering, cryptocurrency theft, and workforce infiltration demonstrates how nation-state actors are adapting to remote work environments, making traditional perimeter security insufficient against threats that exploit human trust and legitimate business processes.
Attack Path Analysis
WaterPlum actors posed as AI/cryptocurrency employers to deliver malicious payloads during fake interviews, compromising over 30,000 devices globally. They established persistent access through social engineering, escalated privileges on infected systems, moved laterally across corporate networks, maintained command and control infrastructure, and exfiltrated cryptocurrency worth nearly $11 million from over 7,000 wallets. The operation caused significant financial impact while supporting broader North Korean IT worker infiltration campaigns.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers impersonated legitimate AI, cryptocurrency, and NFT companies to target software developers and IT professionals through fake job opportunities and recruiting services, delivering malicious payloads during the interview process
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Match Legitimate Name or Location
Domains
Credentials from Web Browsers
Exfiltration Over C2 Channel
Stored Data Manipulation
Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Identity Governance
Control ID: ID.GV-3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Identity Management
Control ID: A.5.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Primary target of WaterPlum's social engineering campaigns posing as AI/crypto employers, requiring enhanced egress security and zero trust segmentation for developer workstations.
Information Technology/IT
IT professionals globally targeted through fake job opportunities, with 30,000+ infected devices necessitating threat detection capabilities and encrypted traffic monitoring for remote access.
Venture Capital/VC
Cryptocurrency theft operations targeting crypto wallets and NFT companies require robust egress filtering and anomaly detection to prevent $11M+ equivalent losses to investors.
Financial Services
Japanese cryptocurrency exchanges specifically compromised through overlapping IP infrastructure, demanding multicloud visibility controls and intrusion prevention systems for transaction security.
Sources
- International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, datahttps://cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/Verified
- Joint Cybersecurity Advisory: DPRK Cyber Actors Target Cryptocurrency and IT Professionals with Social Engineering Campaignshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-026aVerified
- FBI Alert: North Korean Cyber Actors Use Social Media Platforms and Freelancing Websites to Target Cryptocurrency Companieshttps://www.fbi.gov/news/press-releases/fbi-alert-north-korean-cyber-actors-use-social-media-platforms-and-freelancing-websites-to-target-cryptocurrency-companiesVerified
- North Korean IT Workers: Identity Theft and Evasion Schemeshttps://www.treasury.gov/ofac/downloads/sdnlist.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained the WaterPlum campaign's massive lateral spread and cryptocurrency theft by implementing workload segmentation and controlled egress paths. The attack's ability to compromise over 30,000 devices across corporate networks would likely have been significantly reduced through east-west traffic enforcement and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise through social engineering may still occur, workload isolation would likely limit the attacker's ability to establish widespread persistent access across cloud and hybrid environments immediately after initial infection.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely constrain privilege escalation attempts by limiting administrative access paths and reducing the scope of elevated permissions available to compromised accounts within segmented network zones.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely significantly reduce the attacker's ability to move laterally across network segments, constraining their reach from the initial 30,000 compromised devices to a much smaller subset of accessible systems.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely detect and constrain persistent C2 communications by identifying suspicious outbound traffic patterns and blocking unauthorized connections to known malicious infrastructure across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain large-scale cryptocurrency transfers by detecting and blocking suspicious outbound financial transactions, significantly reducing the volume of funds that could be exfiltrated to external accounts.
While some cryptocurrency theft may still occur from initially compromised systems, the overall financial impact would likely be substantially reduced due to constrained lateral reach and limited access to the full scope of targeted cryptocurrency infrastructure.
Impact at a Glance
Affected Business Functions
- Cryptocurrency Trading and Exchange Operations
- Software Development and IT Services
- Digital Asset Management
- Blockchain and NFT Platform Operations
Estimated downtime: 7 days
Estimated loss: $11,000,000
Compromised credentials and authentication data from over 30,000 devices across 100+ countries. Stolen cryptocurrency wallet private keys and seed phrases from approximately 7,000 crypto wallets. Potential exposure of proprietary source code, development projects, and intellectual property from targeted IT professionals and software developers. Personal and professional information of job seekers in AI, cryptocurrency, and NFT industries.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent lateral movement between compromised endpoints and cryptocurrency infrastructure
- • Deploy egress security controls with FQDN filtering to block unauthorized cryptocurrency transfers and data exfiltration to foreign destinations
- • Enable multicloud visibility and anomaly detection to identify suspicious automation patterns and repeated malformed requests from compromised devices
- • Establish encrypted traffic inspection capabilities to detect covert command and control communications through HPE and inline IPS
- • Implement threat detection and anomaly response systems to baseline normal behavior and alert on remote access tools like AnyDesk used by North Korean actors



