North Korea's WaterPpum Group Steals Millions in Crypto via Fake Job Interviews
A North Korean state-backed hacker group has been linked to a massive cryptocurrency heist that saw millions of dollars stolen from victims across 100 countries. The group, known as WaterPpum, used fake job interviews to infect over 30,000 computers with malware that harvested personal identification documents and cryptocurrency private keys.
According to the Japanese National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI), in a joint security advisory issued September 18, WaterPpum targeted software developers, web designers, and cryptocurrency specialists on job platforms and social media by posing as recruiters from legitimate AI, blockchain, and tech recruitment companies.
During fake technical interviews or coding assessments, candidates were instructed to download malicious software disguised as coding tests or video conferencing troubleshooting tools. Once executed, the code delivered backdoor trojans and information-stealing malware, allowing hackers to steal cryptocurrency private keys and transfer funds into North Korean-controlled wallets.
The campaign compromised at least 30,000 devices worldwide, compromising more than 7,000 cryptocurrency wallets and funneling at least $10.71 million in digital assets into North Korean-controlled wallets between late 2025 and July 2026.