Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeBusiness › North Korean fake recruiters infect 30K devices, steal $10.7M in crypto
Business

North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

By Diego Whitfield · · 2 min read

A North Korean cyber operation has infected roughly 30,000 devices worldwide and pilfered $10.7 million in cryptocurrency by luring software developers with counterfeit job offers, according to newly reported findings.

How the Scheme Worked

The group, tracked as WaterPlum, posed as recruiters from crypto, artificial intelligence and NFT companies to bait developers into engaging with malicious materials. Targets were approached with what appeared to be legitimate employment opportunities, only to have their systems compromised during the fake hiring process.

Investigators say the campaign reached victims in more than 100 countries, underscoring the global scale of the effort. By masquerading as hiring managers, the attackers exploited the trust developers place in recruitment outreach, a tactic that has become increasingly common among state-linked hacking crews.

Fake job offers have become one of North Korea's most effective weapons for draining crypto wallets.

The malware planted on infected machines allowed the group to siphon digital assets, ultimately netting millions in stolen funds. The technique blends social engineering with technical intrusion, making it harder for individual users to detect the threat before damage is done.

A Growing Pattern

WaterPlum's operation fits a broader trend of North Korean threat actors focusing on the cryptocurrency sector to generate revenue. These groups have repeatedly used elaborate impersonation schemes to reach developers, engineers and other technical staff who often have access to valuable digital assets or sensitive infrastructure.

Security researchers have warned that the recruitment-themed approach is especially dangerous because it targets professionals through channels they consider routine and trustworthy. The scale of this latest campaign highlights how much damage a single coordinated effort can inflict.

Key details of the campaign include:

  • At least 30,000 devices compromised
  • Victims spread across more than 100 countries
  • An estimated $10.7 million in crypto stolen
  • Targets drawn from the crypto, AI and NFT industries

Experts continue to urge developers to verify recruiter identities, avoid running unfamiliar code from job applications, and treat unsolicited employment offers with caution.

Was this useful?👍 Yes👎 No