North Korean Hackers Impersonate Recruiters to Steal Crypto Assets
The North Korean hacking group WaterPlum has been using fake job offers to steal crypto assets from individual developers, freelancers, and Web3 professionals. According to a joint disclosure by Japan's National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI), WaterPlum impersonated recruiters or cryptocurrency companies to lure victims into running malicious code under the guise of programming tests and project collaboration.
Between December 2025 and July 2026, the group infected over 30,000 devices in more than 100 countries, transferring funds or stealing account credentials from over 7,000 cryptocurrency wallets, involving at least $10.71 million in crypto assets.
The most common entry point for WaterPlum attacks is a seemingly legitimate job opportunity. Attackers impersonate AI, cryptocurrency, or NFT companies, reaching out to software developers via social media, online job platforms, gig platforms, and freelance marketplaces.
During the 'technical assessment' phase, attackers send job candidates a code repository asking them to run the project locally, fix bugs, or troubleshoot issues with video conferencing software. The real attack occurs here, as the projects contain malicious code.