Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M

    12 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    North Korean Fake Recruiters Compromise 30k Devices, Steal $10.7m
    North Korean Fake Recruiters Compromise 30k Devices, Steal $10.7m

    North Korea-linked cyber group WaterPlum, also known as “Contagious Interview,” is accused of stealing at least $10.7 million by impersonating recruiters for legitimate cryptocurrency and AI companies. According to a joint advisory cited by authorities in Japan, Germany, Australia and the United States, the operation targets software and IT professionals worldwide, using malware delivered during fake hiring workflows.

    The campaign blends social engineering with direct technical compromise: victims are lured through recruiting channels and then tricked into downloading and running malicious files disguised as coding tasks or “fixes” for video-conferencing problems. Once attackers gain access, they use remote access tools and infostealing malware to extract both data and cryptocurrency.

    Key takeaways

    • At least $10.7 million stolen, according to the joint advisory, via a fake recruitment scheme tied to WaterPlum.
    • More than 30,000 device infections across over 100 countries were attributed to the group.
    • 7,000+ cryptocurrency wallets affected between December 2025 and July 2026, with funds or credentials reportedly extracted.
    • The lure is professional hiring: attackers impersonate AI, crypto and Web3 companies and sometimes leverage recruiting services.
    • Secondary harm extends beyond theft, including identity document misuse and opportunities for impersonation, extortion, or further infiltration.

    Recruitment scams as an entry point to crypto targets

    In the advisory referenced by participating governments, WaterPlum is described as focusing on individuals such as web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The group reportedly uses social media, mainstream job platforms, gig work marketplaces, and freelance sites to reach candidates—then attempts to move victims into a “recruiting process” that culminates in malicious execution.

    Authorities say the attackers impersonate legitimate companies, including those described as operating in the AI, cryptocurrency and NFT space. In some cases, the advisory also notes the use of recruiting services as part of the deception, potentially making the campaign look more credible to applicants who may be unfamiliar with threat patterns.

    Malware delivery disguised as work tasks

    The advisory describes a workflow designed to lower victims’ suspicion. During recruitment, job seekers are reportedly instructed to download and execute malicious files that are presented as coding assignments or as troubleshooting materials, including alleged fixes for video-conferencing errors.

    This matters for organizations and candidates because it turns a common administrative step—reviewing a “take-home” task or installing something to support an interview or call—into a high-risk trigger. For employers in the crypto and AI sector, it also increases the chance that a compromised machine becomes the starting point for a deeper breach, not just an isolated incident.

    Backdoor access, data theft, and wallet compromise

    Once infections succeed, WaterPlum is said to establish backdoor access to a victim’s device. The advisory attributes subsequent activity to the use of remote-access trojans alongside infostealing malware to exfiltrate sensitive information and cryptocurrency-related assets.

    In terms of scale, the advisory claims that WaterPlum infected at least 30,000 devices in more than 100 countries. It also alleges that between December 2025 and July 2026, the group extracted funds or account credentials from over 7,000 cryptocurrency wallets.

    While these figures indicate substantial operational reach, the advisory also emphasizes that the campaign’s purpose is broader than direct theft. Stolen identity documents and other personal data can enable attackers to impersonate victims, pursue employment or access opportunities, and potentially support extortion efforts.

    Linked to North Korea’s use of IT access inside foreign firms

    The advisory links WaterPlum to North Korea’s wider pattern of placing IT workers into foreign organizations. Japanese and US authorities assess that WaterPlum actors—and at least some North Korean IT workers—operate under North Korea’s Munitions Industry Department.

    The report also includes an example in which a suspected North Korean IT worker applied to a role at a Japanese crypto exchange using a forged resume. Authorities said the exchange rejected the applicant after inconsistencies surfaced during interviews, including an inability to discuss skills listed on the resume in detail.

    More recently, Cointelegraph previously reported a case involving Consensys, which had unknowingly engaged a North Korea-linked developer as a consultant. Cointelegraph reported that the company terminated the individual’s access after identifying the threat. In that case, an investigation reportedly found no evidence of asset or data theft, malicious code deployment, or impact on user safety.

    Taken together, these examples reinforce a recurring asymmetry: even when companies stop short of a full compromise, the recruitment stage itself can still create risk—through compromised endpoints, identity fraud, and attempts to gain legitimate access to organizations that handle crypto-adjacent workflows.

    Why the story matters for crypto teams now

    WaterPlum’s alleged tactics arrive amid continuing concern from US authorities about North Korea’s persistent efforts to use cyber operations and cryptocurrency theft to fund activity. The advisory references years of warnings and enforcement, and earlier coverage highlighted claims that the FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025. It also points to US Treasury statements warning about undercover IT workers dating back to at least 2018.

    For crypto employers and candidates, the practical takeaway is that security scrutiny needs to extend beyond “obvious” phishing. Recruitment processes—especially those involving coding tasks, file downloads, or remote collaboration—should be treated as an attack surface. Conducting verification steps, using safe sandboxing for any executables, and ensuring that sensitive systems are protected against endpoint compromise can reduce the chance that a job offer becomes a foothold.

    Readers should watch next for whether regulators and major crypto organizations publish updated hiring security guidance in response to the advisory’s details, and whether more victims or additional campaigns linked to WaterPlum are identified—particularly around the reported wallet credential extractions and the use of stolen identities for follow-on access.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Arb Price Signals Spur Speculation Of 70x Upside In Hodler Digest

    ARB Price Signals Spur Speculation of 70x Upside in Hodler Digest

    2 hours ago
    Trump Announces ‘ai Force’ Plan, Appoints Ai ‘czar’ To Guide Policy

    Trump Announces ‘AI Force’ Plan, Appoints AI ‘Czar’ to Guide Policy

    12 hours ago
    Trump Signals New Us “ai Force” And Plans To Name Ai Czar: Reports

    Trump Signals New US “AI Force” and Plans to Name AI Czar: Reports

    13 hours ago
    Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market

    Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market

    14 hours ago
    Anthropic Selects Accenture For Embedded Ai Evaluation In Slowdown Plan

    Anthropic Selects Accenture for Embedded AI Evaluation in Slowdown Plan

    14 hours ago
    Grayscale Files Zcash Etf For 3-For-1 Forward Share Split

    Grayscale Files Zcash ETF for 3-for-1 Forward Share Split

    15 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M
    • ARB Price Signals Spur Speculation of 70x Upside in Hodler Digest
    • Trump Announces ‘AI Force’ Plan, Appoints AI ‘Czar’ to Guide Policy
    • Trump Signals New US “AI Force” and Plans to Name AI Czar: Reports
    • Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market
    • Anthropic Selects Accenture for Embedded AI Evaluation in Slowdown Plan
    • Grayscale Files Zcash ETF for 3-for-1 Forward Share Split
    • Grayscale Files Zcash ETF Proposal for 3-for-1 Forward Split
    • Anthropic Selects Accenture as Embedded Evaluator for AI Slowdown Plan
    • Kalshi Files to Launch US Crypto-Linked Perpetual Futures on Coinbase

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Tangem 300x300
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!