North Korean Hackers Use Fake Jobs to Infect 30,000 Devices and Steal $10M in Crypto
A North Korea-linked hacking group has been linked to a massive cyberattack that infected over 30,000 devices in more than 100 countries. The WaterPlum group targeted software developers and IT professionals through fake job offers at legitimate-looking crypto, blockchain, AI, and NFT companies.
The attackers posed as recruiters on social media, job websites, freelance marketplaces, and recruitment platforms. Victims were lured into downloading malicious files disguised as coding tests or fixes for video-call problems.
Around 7,000 cryptocurrency wallets were compromised between December 2025 and July 2026, with at least $10.71 million in stolen cryptocurrency transferred to North Korea.