$10.7M Heist: North Korean Hackers Pose as Crypto Recruiters to Steal Funds
A North Korean hacking group known as WaterPlum has stolen at least $10.7 million by posing as recruiters for legitimate crypto and AI companies.
The group, also referred to as Contagious Interview, targets software developers and IT professionals worldwide, according to a joint advisory from Japan, Germany, Australia, and the US.
Authorities said the fake recruiters impersonated legitimate AI, cryptocurrency or non-fungible token (NFT) companies and used recruiting services to lure job seekers through social media platforms, online job platforms, gig work platforms, or freelance marketplaces.
The victims were instructed to download and execute malicious files disguised as coding assignments or fixes for video-conferencing errors, which allowed the hackers to gain backdoor access to the victim's computer and steal sensitive data and cryptocurrency.