Urgent.News

What's breaking now, across thousands of outlets.

Tech

North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.

North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

North Korean hacking group WaterPlum, also known as Contagious Interview, has targeted developers with fake job offers from crypto, AI, and NFT companies, infecting over 30,000 devices in more than 100 countries. These fake recruiters, impersonating legitimate AI, cryptocurrency, or NFT companies, have stolen at least $10.7 million by luring unsuspecting job seekers with malware.

The group primarily targets web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. WaterPlum's tactics include recruiting on social media, online platforms, gig work platforms, or freelance marketplaces. Once inside a victim's computer, they use remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency.

The damage extends beyond stolen cryptocurrency, as stolen identity documents can enable North Korean IT workers to impersonate victims and earn income, or sensitive information can be used for extortion.

Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at cointelegraph.com →

More in Tech

I Built a Multi-Region Pilot Light on AWS. The Diagram Was the Easy Part.

Most disaster recovery write-ups stop at the diagram. You get two boxes, an arrow labelled "replicate", and an RTO that was never measured.

  • Route 53 monitors health every 10 seconds, switches DNS to secondary region on failure
  • Failover process promotes read replica database, scales Auto Scaling group in both regions

More from Monday 21 September →