North Korean Hackers Use Fake Job Ads to Steal Crypto Worth Millions
A North Korean hacking group called WaterPlum has been using job ads to harvest sensitive information from unsuspecting applicants in hundreds of countries, according to authorities. The group infiltrated at least 30,000 devices and stole $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts.
Between December 2025 and July this year, members of WaterPlum presented as an employer advertising fake roles for software developers and IT professionals. They would instruct applicants to download files for software alternatives to video conferencing apps like Zoom to conduct interviews.
Cybersecurity officials from the US, Japan, Germany, and Australia issued a joint statement warning that the group was targeting individual IT professionals. The group also used artificial intelligence (AI) face-swapping software during online interviews and asked applicants to disable their camera 'because of network issues.'
The University of Melbourne's Andrew Cullen said this type of scam has been accelerating, with fake North Korean employees reported in the last three to four years. He warned that it's difficult for governments and cybersecurity organisations to collect large-scale data on the problem.