North Korea-Linked Hackers Use Fake Jobs to Steal ¥1.7B in Cryptocurrency
A North Korea-linked hacking group known as WaterPlum has been using fake job offers to target IT workers and steal cryptocurrency. The group posed as recruiters for companies working in AI, crypto, and NFTs, contacting developers through social media, job websites, and freelance platforms.
Attackers sent technical interviews or coding assignments that included embedded malicious code in some files. Some applicants received development files or projects and were asked to run code while completing the tasks. The group compromised data tied to over 7,000 crypto wallets.
From December 2025 through July 2026, WaterPlum infected more than 30,000 devices across over 100 countries. At least ¥1.7 billion in cryptocurrency was moved to wallets controlled by the group, according to Japan's NPA.