Loading IndicatorLoading Indicator

North Korea-Linked WaterPlum Posed as Crypto, AI Recruiters, Stole at Least $10.7 Million

Source
Suehyeon Lee

Summary

  • The North Korea-linked hacking group WaterPlum stole at least $10.7 million by posing as recruiters at cryptocurrency and artificial intelligence (AI) companies.
  • WaterPlum impersonated recruiters at real AI, cryptocurrency and non-fungible token (NFT) companies or used legitimate hiring services to target specialists in cryptocurrency, blockchain and Web3.
  • WaterPlum infected at least 30,000 devices in more than 100 countries and compromised funds and account credentials from more than 7,000 crypto wallets.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator
Photo: Shutterstock
Photo: Shutterstock

A North Korea-linked hacking group known as WaterPlum posed as recruiters for cryptocurrency and artificial intelligence companies, spread malware to job seekers and stole at least $10.7 million, Cointelegraph reported.

On September 21, Cointelegraph cited a recent joint cybersecurity advisory from authorities in Japan, Germany, Australia and the US as saying WaterPlum, also known as Contagious Interview, had targeted software developers and information technology professionals worldwide.

WaterPlum approached victims by impersonating recruiters at real AI, cryptocurrency and non-fungible token companies or by using legitimate hiring services. Its main targets included web designers, engineers and specialists in crypto, blockchain and Web3.

The hackers contacted job seekers through social media, online job sites and freelance platforms. During the hiring process, they persuaded candidates to run malicious files disguised as coding tests or software meant to fix video-conferencing problems.

After gaining access to victims' computers, the attackers used remote-access trojans and information-stealing malware to take sensitive data and crypto assets. Authorities said they also secured a route into the internal systems of companies employing the infected developers.

According to the advisory, WaterPlum infected at least 30,000 devices in more than 100 countries from December 2025 through July 2026. Funds or account credentials were compromised from more than 7,000 crypto wallets, and confirmed losses reached at least $10.7 million.

Authorities also raised the possibility that the stolen personal data could be used to help North Korean IT workers disguise their identities. Stolen identification documents could be used to impersonate victims, earn income from overseas companies or use sensitive information for extortion, they said.

The advisory also linked WaterPlum's activity to North Korea's strategy of infiltrating overseas IT workforces. Authorities in Japan and the US believe members of WaterPlum and some North Korean IT workers operate under North Korea's Munitions Industry Department.

In one case at a Japanese crypto exchange, an applicant suspected of being a North Korean IT worker applied for an engineering role with a falsified resume. The exchange declined to hire the candidate after finding discrepancies during the interview, including an inability to explain in detail the skills listed on the resume.

Cointelegraph reported in July that Consensys had hired a North Korea-linked developer as a consultant. Consensys said it blocked the individual's access after confirming the issue, and an investigation found no theft of assets or data, no malware distribution and no impact on user safety.

#Incidents
Suehyeon Lee

Suehyeon Lee

shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.

What do you think about this news?








PiCK News






Hashtag News