North Korea-Linked Hackers Use Fake Job Interviews to Steal Crypto Assets
A North Korea-linked hacking group called WaterPlum has been distributing malware to software developers and IT professionals through fake job interviews. The attacks, which began in May 2025, have resulted in over 30,000 devices being infected across more than 100 countries, with funds and authentication credentials compromised from over 7,000 cryptocurrency wallets.
The group's tactics involve impersonating companies in AI, cryptocurrency, and NFT sectors or recruitment agencies to lure victims into downloading malicious code disguised as necessary work materials. Once the malware is installed, it can steal passwords, keystrokes, screenshots, seed phrases used to restore cryptocurrency wallets, and passport images stored on the device.
The attackers use AI face-swapping software during interviews and text-to-speech tools to practice Japanese pronunciation, making their operations highly sophisticated. They also employ 'laptop farms' to make it appear that North Korean IT workers are connecting from within Japan while actually being overseas.