North Korean state-linked hackers have siphoned roughly $11 million from more than 7,000 cryptocurrency wallets using elaborate fake job interviews, according to a new joint advisory from seven international agencies that connects the operation directly to Pyongyang's intelligence apparatus.
How the Scheme Works
The campaign relies on social engineering rather than brute-force technical attacks. Operatives pose as recruiters offering lucrative positions to developers, engineers, and crypto professionals, then lure targets into fake interview processes. During these interactions, victims are tricked into downloading malicious software or running code disguised as technical assessments, handing attackers access to their devices and, ultimately, their digital assets.
The advisory attributes the activity to a hacking crew tracked as WaterPlum, which investigators have now linked to the same government bureau that oversees North Korea's sprawling remote IT worker program. That connection suggests the two long-running operations are not separate efforts but coordinated arms of a single state-directed strategy to generate revenue and infiltrate foreign companies.
Seven agencies now agree: the fake interviews and the covert IT workers answer to the same masters in Pyongyang.
A Coordinated State Operation
By funneling stolen funds from thousands of individual wallets, North Korea has quietly assembled an eight-figure haul, underscoring how effective low-tech deception can be against even security-conscious crypto users. The scale — over 7,000 compromised wallets — points to an industrialized approach rather than isolated opportunistic hacks.
The joint advisory represents an unusual show of unity among international authorities, who have increasingly warned that Pyongyang treats crypto theft as a core funding mechanism for its weapons programs. Officials say the remote IT worker scheme, in which North Koreans use false identities to land jobs at Western firms, often overlaps with these theft campaigns.
Key takeaways from the advisory include:
- The WaterPlum crew and the IT worker program share the same controlling bureau.
- Fake job interviews serve as the primary infection vector.
- Roughly $11 million was drained from more than 7,000 wallets.
What It Means for the Industry
For crypto professionals, the findings reinforce warnings to treat unsolicited recruitment offers with extreme caution, particularly any that require downloading files or executing code. Security researchers have repeatedly flagged interview-based l
