Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    North Korean Phishing Crew Hits 30K Devices, Steals $10.7M Crypto

    1 minute ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    North Korean Phishing Crew Hits 30k Devices, Steals $10.7m Crypto
    North Korean Phishing Crew Hits 30k Devices, Steals $10.7m Crypto

    North Korea-linked hacking group WaterPlum—also tracked as “Contagious Interview”—has stolen at least $10.7 million by tricking job seekers into installing malware under the guise of recruitment for legitimate crypto and AI companies, according to a joint cyber advisory issued by authorities in Japan, Germany, Australia, and the United States.

    The campaign, which has targeted software developers and IT professionals across multiple countries, combines fake hiring workflows with malicious files that grant attackers remote access to victims’ systems, enabling the theft of cryptocurrency and other sensitive information.

    Key takeaways

    • WaterPlum used fake recruiter identities and recruitment services to impersonate real crypto, blockchain, AI, and Web3 companies.
    • Victims were commonly directed to download and run malware disguised as coding tasks or fixes for video-conferencing problems.
    • Authorities link the group to a broader North Korean strategy of placing IT workers inside foreign organizations.
    • Reported impact includes at least 30,000 infected devices in more than 100 countries and theft from over 7,000 crypto wallets between December 2025 and July 2026.
    • Beyond financial theft, stolen documents and personal data can be leveraged for impersonation, extortion, or follow-on access to employers.

    Fake recruitment as the entry point

    In the advisory, the involved authorities describe WaterPlum’s targeting of web designers, engineers, and specialists working in cryptocurrency, blockchain, and Web3-related technologies.

    According to the report, attackers reached out through social media, online job platforms, gig work services, and freelance marketplaces. Once a candidate engaged, the impostors allegedly instructed the victim to download and execute malicious files, framing them as either coding assignments or troubleshooting steps for video-conferencing errors.

    While recruitment scams are not new, this campaign’s focus on technical roles and blockchain-specific expertise increases the odds of victims being persuaded by the “work assignment” narrative—especially when malicious files are disguised as development deliverables.

    From malware to wallet theft and data exfiltration

    The advisory says the scheme went beyond deception and culminated in compromise. After gaining backdoor access to a victim’s computer, WaterPlum operators reportedly used remote-access tools and infostealing malware to exfiltrate sensitive data and cryptocurrency.

    The attackers also created a pathway for further infiltration: successful infections can allow WaterPlum to compromise organizations that employ the recruited developers, particularly if the victim is granted access to internal systems, source code, or related accounts.

    Authorities estimate that WaterPlum infected at least 30,000 devices across more than 100 countries. During the period from December 2025 through July 2026, the advisory attributes extraction of funds or credentials from over 7,000 cryptocurrency wallets.

    For users and employers, the key risk is that credential or wallet compromise may not be confined to a single endpoint. If logins, signing keys, or operational details are harvested, attackers can potentially move from theft to sustained access or further fraud.

    Why the threat extends beyond crypto theft

    The joint advisory emphasizes that the harm can be broader than stolen cryptocurrency. It warns that identity documents taken from victims can enable North Korean IT workers to impersonate those individuals and generate income, while other harvested information could be used for extortion.

    The advisory also links WaterPlum’s activity to North Korea’s longer-running effort of embedding IT workers inside foreign organizations. Japanese and US authorities, according to the report, assess that WaterPlum actors—and some North Korean IT workers—operate under North Korea’s Munitions Industry Department.

    In that context, a recruitment-driven malware campaign can serve a dual function: stealing funds in the short term and supporting infiltration or fraud in the longer term—particularly when victims’ identities are compromised.

    Real-world cases highlight operational tradecraft

    The advisory describes a suspected North Korean IT worker applying for an engineering role at a Japanese crypto exchange using a forged resume. Authorities say the exchange rejected the applicant after discrepancies emerged during the interview, including the candidate’s inability to explain skills listed on the document in detail.

    More recently, earlier reporting from Cointelegraph documented an incident involving Consensys, which unknowingly engaged a North Korea-linked developer as a consultant. Cointelegraph reported that Consensys terminated access after discovering the threat, and that an investigation found no theft of assets or data, no deployment of malicious code, and no impact on user safety.

    Together, these cases underline a common pattern: recruitment-related infiltration attempts may be caught before they result in damage, but they still create enough risk to require stronger screening, particularly for roles tied to crypto operations and sensitive technical work.

    Part of a wider North Korea funding and infiltration playbook

    The WaterPlum campaign is presented as another example of North Korea’s persistent use of cryptocurrency-related theft to raise funds, even amid years of warnings and enforcement efforts.

    Cointelegraph notes that the FBI previously blamed North Korea for a $1.5 billion Bybit theft reported in February 2025. US authorities, meanwhile, have warned about North Korea’s undercover IT workers since at least 2018, according to the same coverage.

    What makes the WaterPlum advisory particularly significant is the blend of financial criminality and human infrastructure infiltration. The malware delivery method—tied to job hunting—shows how attackers attempt to exploit legitimate hiring processes in a sector where technical trust and remote work are common.

    Going forward, the most important open question for organizations is how quickly and consistently recruitment-related compromises are detected—especially when malware is introduced through “normal” workflows like coding assignments and conferencing fixes. Readers should watch for additional advisories detailing mitigation steps, and employers should treat suspicious recruitment paths as a cyber incident risk, not just a fraud concern.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    North Korean Fake Recruiters Compromise 30k Devices, Steal $10.7m

    North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M

    1 hour ago
    Arb Price Signals Spur Speculation Of 70x Upside In Hodler Digest

    ARB Price Signals Spur Speculation of 70x Upside in Hodler Digest

    3 hours ago
    Trump Announces ‘ai Force’ Plan, Appoints Ai ‘czar’ To Guide Policy

    Trump Announces ‘AI Force’ Plan, Appoints AI ‘Czar’ to Guide Policy

    13 hours ago
    Trump Signals New Us “ai Force” And Plans To Name Ai Czar: Reports

    Trump Signals New US “AI Force” and Plans to Name AI Czar: Reports

    14 hours ago
    Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market

    Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market

    15 hours ago
    Anthropic Selects Accenture For Embedded Ai Evaluation In Slowdown Plan

    Anthropic Selects Accenture for Embedded AI Evaluation in Slowdown Plan

    15 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • North Korean Phishing Crew Hits 30K Devices, Steals $10.7M Crypto
    • North Korean Fake Recruiters Compromise 30K Devices, Steal $10.7M
    • ARB Price Signals Spur Speculation of 70x Upside in Hodler Digest
    • Trump Announces ‘AI Force’ Plan, Appoints AI ‘Czar’ to Guide Policy
    • Trump Signals New US “AI Force” and Plans to Name AI Czar: Reports
    • Lemon Exits Brazil As Licensing Capital Rules Reshape Crypto Market
    • Anthropic Selects Accenture for Embedded AI Evaluation in Slowdown Plan
    • Grayscale Files Zcash ETF for 3-for-1 Forward Share Split
    • Grayscale Files Zcash ETF Proposal for 3-for-1 Forward Split
    • Anthropic Selects Accenture as Embedded Evaluator for AI Slowdown Plan

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Ledger
    Crypto.com

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Ledger
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!