Loading IndicatorLoading Indicator

PiCK

North Korea-Linked WaterPlum Posed as Crypto, AI Recruiters, Stole at Least $10.7 Million

Source

Summary

  • North Korea-linked hacking group WaterPlum stole at least $10.7 million by posing as recruiters at cryptocurrency and artificial intelligence (AI) companies.
  • WaterPlum posed as recruiters at real AI, cryptocurrency and non-fungible token (NFT) companies to target software developers and information technology (IT) professionals worldwide, compromising funds and credentials from more than 7,000 crypto wallets.
  • Authorities warned investors and companies to strengthen cybersecurity, saying stolen personal data could be used to disguise the identities of North Korean IT workers and then generate income at overseas crypto exchanges or be used for blackmail.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

A North Korea-linked hacking group known as WaterPlum posed as recruiters for cryptocurrency and artificial intelligence companies, spread malware to job seekers and stole at least $10.7 million, Cointelegraph reported.

Citing a recent joint cybersecurity advisory, Cointelegraph said on September 21 that authorities in Japan, Germany, Australia and the US identified WaterPlum, also known as Contagious Interview, as being behind attacks targeting software developers and information technology professionals worldwide.

WaterPlum approached victims by impersonating recruiters at legitimate AI, cryptocurrency and non-fungible token companies, or by using legitimate hiring services. Its main targets included web designers, engineers and other specialists in cryptocurrency, blockchain and Web3.

The hackers contacted job seekers through social media, online job sites and freelance platforms. During the hiring process, they persuaded victims to run malicious files disguised as coding assignments or software intended to fix video-conference problems.

After gaining access to victims' computers, the group used remote-access trojans and information-stealing malware to steal sensitive data and crypto assets. Authorities said the campaign also created a route into the internal systems of companies that employed infected developers.

Authorities said WaterPlum infected at least 30,000 devices in more than 100 countries from December 2025 through July 2026. During that period, funds or account credentials were compromised from more than 7,000 crypto wallets, and confirmed losses totaled at least $10.7 million.

Authorities also warned that stolen personal data could be used to help North Korean IT workers conceal their identities. They said stolen identification documents could be used to impersonate victims, earn income at overseas companies or use sensitive information for blackmail.

The advisory also linked WaterPlum's activity to North Korea's strategy of placing IT workers overseas. Authorities in Japan and the US believe WaterPlum operatives and some North Korean IT workers operate under North Korea's Munitions Industry Department.

In one case at a Japanese crypto exchange, a job applicant suspected of being a North Korean IT worker applied for an engineering position using a falsified resume. The exchange declined to hire the applicant after finding inconsistencies in the interview, including an inability to explain in detail the skills listed on the resume.

Cointelegraph also reported in July that Consensys had hired a North Korea-linked developer as a consultant. After confirming the matter, Consensys blocked the individual's access and said its investigation found no theft of assets or data, no malware distribution and no impact on user safety.

#Crypto Hack
#North Korea Hacking

shlee@bloomingbit.ioHello, I'm a reporter at bloomingbit

What do you think about this news?








PiCK News






Hashtag News