North Korean hackers infected 30,000 devices worldwide by posing as tech recruiters
The WaterPlum group posed as tech recruiters to trick developers into downloading malware, stealing funds from more than 7,000 cryptocurrency wallets
North Korean hackers, known as WaterPlum or Contagious Interview, posed as tech recruiters to trick developers into downloading malware. They targeted software developers and IT professionals worldwide with fake job listings at companies focused on cryptocurrency, AI, and NFTs. The hackers used social media, online job platforms, and freelance marketplaces to lure job seekers.
The fake recruitment process involved virtual technical interviews or coding assignments, which led to the download and execution of malicious files. Once a device or network was infected, the hackers used malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. According to Slashdot, over 30,000 devices in more than 100 countries were infected, resulting in over 7,000 compromised cryptocurrency wallets and more than $10 million transferred to North Korea.
The hacking campaign, which occurred from December 2025 through July 2026, was attributed to North Korea's Munitions Industry Department. US, Japanese, Australian, and German authorities issued a joint cybersecurity advisory warning about the group's tactics. Cointelegraph reported that the hackers stole at least $10.7 million.
Brief written by urgent.news from Quartz, Slashdot, Cointelegraph, Inc. — 4 reports on this story. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Nations take action on North Korean IT workers after UN report therecord.media