North Korean Hacking Group WaterPlum Steals $10.7M Through Fake Job Interviews
North Korea's threat to the crypto industry has escalated significantly in recent months. According to a report by Japan's National Police Agency (NPA) and the U.S Federal Bureau of Investigation (FBI), North Korean state-backed group WaterPlum stole $10.7M through fake headhunting schemes.
The group, which appears to be designed for wide-scale fake recruitment schemes to deliver malware and steal crypto assets, posed as hiring managers for crypto firms, NFT businesses, and artificial intelligence companies. They reached out to IT and software developers with a fake skill test that duped the victims into downloading malicious programs that drained their wallets.
Separately, WaterPlum also posed as employees and bagged lucrative offers with crypto firms only to gain access to their systems and compromise them. The group infiltrated 30K devices across over 100 countries, affecting over 7000 crypto wallets in an eight-month period from December 2025 to July 2026.
North Korea's evolving crypto heist strategy has been tracked by most security firms, with WaterPlum being one of the threat actors backed by the country. The group is not the only high-value operator, as the Lazarus Group and AppleJesus have also carried out significant hacks in recent years.