Crypto news report · source clearly identified

North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.

North Korean hacking group WaterPlum, also known as Contagious Interview, used fake recruitment offers to compromise developers worldwide. The campaign resulted in at least 30,000 infected devices and the theft of roughly $10.7 million from cryptocurrency wallets.

Recruitment‑based malware distribution

WaterPlum posed as recruiters for legitimate crypto, AI and NFT firms, contacting job seekers on social media, job boards and freelance platforms. Victims were asked to download files presented as coding assignments or video‑conferencing fixes. Once executed, the files installed remote‑access trojans and infostealing malware, giving the attackers backdoor access.

Scale of the operation

  • Infections: ≥ 30,000 devices in over 100 countries.
  • Timeframe: December 2025 – July 2026.
  • Crypto theft: Funds or credentials from > 7,000 cryptocurrency wallets, totaling about $10.7 million.

Beyond cryptocurrency theft

The stolen identity documents enable the actors to impersonate victims for additional income or extortion. Cases were reported where forged resumes were used to apply for engineering roles at a Japanese crypto exchange and a consultancy engagement with ConsenSys, which was terminated after discovery.

Broader context

The campaign aligns with North Korea’s long‑standing strategy of using cyber‑theft to fund its activities. Previous incidents include the FBI‑attributed $1.5 billion theft from Bybit in February 2025 and ongoing warnings about undercover IT workers since at least 2018.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
September 21, 2026, 1:42 AM
Original headline
North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
View original report ↗