- North Korean Hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate crypto and AI companies.
- The group targeted software developers and IT professionals worldwide with Malware disguised as coding assignments.
- WaterPlum infected over 30,000 devices in more than 100 countries between December 2025 and July 2026.
- Authorities linked the group to North Korea’s Munitions Industry Department and broader IT worker infiltration campaigns.
A North Korean hacking group known as WaterPlum stole at least $10.7 million by impersonating recruiters from legitimate cryptocurrency and Artificial Intelligence companies, Cybersecurity-advisory/20260918-prk-waterplum-node.html” rel=”nofollow noopener” target=”_blank”>according to a joint advisory from Japan, Germany, Australia and the United States. The group, also called Contagious Interview, lured victims through social media, online job platforms, and freelance marketplaces.
During the recruitment process, the group instructed targets to download malicious files disguised as coding assignments or fixes for video-conferencing errors. Once backdoor access was obtained, WaterPlum used remote-access trojans and infostealing malware to exfiltrate cryptocurrency and sensitive data.
Successful infections also allowed the actors to infiltrate organizations employing the unsuspecting developers. The advisory reported that WaterPlum infected at least 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 cryptocurrency wallets.
Consequently, stolen identity documents enabled North Korean IT workers to impersonate victims and earn income, with sensitive information potentially used for extortion. In one case, a suspected North Korean IT worker applied for an engineering role at a Japanese crypto exchange using a forged resume, which was rejected after discrepancies surfaced during the interview.
This campaign is the latest example of North Korea’s persistent use of cryptocurrency theft to raise funds despite years of warnings. The FBI previously blamed North Korea for the $1.5 billion Bybit theft in February 2025, while the US has warned about undercover IT workers since at least 2018.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
