North Korean hacking group WaterPlum compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, stealing over $10.7 million in cryptocurrency. The group, linked to the 'Contagious Interview' campaign, targets job seekers through fake interviews and malicious software packages. A joint advisory from Japanese, US, Australian, and German authorities connects WaterPlum to North Korea's weapons programs and fraudulent IT worker operations.