North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.

North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

A North Korean cyber group known as WaterPlum has conducted a sophisticated recruitment scam that infected at least 30,000 devices across more than 100 countries, resulting in the theft of approximately $10.7 million in cryptocurrency. The operation targeted software developers by posing as recruiters offering positions at companies operating in the crypto, artificial intelligence, and NFT sectors. Victims were lured through fake job offers that ultimately delivered malware capable of compromising their systems and draining digital assets.

WaterPlum is among several North Korean state-linked hacking collectives known to fund the regime's operations through cybercrime. North Korean threat actors have long focused on the cryptocurrency industry, which offers relative anonymity and cross-border transfer capabilities that make stolen funds difficult to trace and recover. Groups such as Lazarus have previously been linked to billions of dollars in crypto theft over recent years.

The scale of this campaign highlights persistent vulnerabilities within the developer community, particularly as remote hiring has become standard practice across the tech industry. The targeting of individuals working at or seeking employment with blockchain and AI firms suggests North Korean operatives are deliberately pursuing those with access to high-value digital wallets and sensitive infrastructure. Security professionals are urging developers to rigorously verify recruiter identities and avoid executing code shared during unsolicited hiring processes.

Authorities and cybersecurity researchers are expected to continue monitoring WaterPlum's activity as the group shows no signs of scaling back its operations.

Source: Cointelegraph

Read original article ↗