North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
North Korean cyber group WaterPlum targeted developers with fake jobs at crypto, AI and NFT companies, infecting at least 30,000 devices across more than 100 countries.
North Korean hacking group WaterPlum stole at least $10.7 million by posing as recruiters for legitimate crypto and AI companies, attacking unsuspecting job seekers with malware.
The group, also known as Contagious Interview, targets software developers and IT professionals worldwide, according to a joint advisory from Japan, Germany, Australia and the US. Authorities said the fake recruiters impersonated legitimate AI, cryptocurrency or non-fungible token (NFT) companies and also used recruiting services.
“The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies,” they added.

