North Korean Hackers Infect Over 30,000 Devices in Massive Crypto Scam
North Korean hackers linked to WaterPlum have been involved in a massive crypto scam that infected over 30,000 devices across more than 100 countries and regions. The campaign, which took place between December 2025 and July 2026, stole data from more than 7,000 crypto wallets.
Authorities found that the hackers used fake recruitment activity to target technology workers, including software developers, engineers, and Web3 professionals. They impersonated legitimate companies on social media and recruitment websites, offering employment opportunities and downloading programs that contained malware.
The stolen information included browser credentials, clipboard contents, screenshots, keystrokes, private keys, and wallet seed phrases. Attackers also targeted driver's licenses, passports, and other identity documents.