North Korean Hackers Steal $10.71M in Crypto as 'Employer' Scam Spreads Globally
Australia's cyber agency and its international counterparts have issued an advisory warning about a North Korean hacking group called WaterPlum. The group, which has been active since December 2025, has infected at least 30,000 devices in over 100 countries and stolen US$10.71 million (AU$15.3 million) in cryptocurrency.
WaterPlum's members pose as employers on job sites, recruiting developers for coding tests. During interviews, candidates are asked to download and run files from code repositories, which contain malware that lifts browser passwords, keystrokes, and wallet seed phrases.
The agencies warn that the stolen funds were moved to North Korea, and that paying North Korean IT workers may breach domestic law and sanctions. Japanese authorities have dismantled a laptop farm run by an enabler in Japan, which hosted work computers controlled remotely by North Korean IT workers.