By Interestana AI Editorial — AI-drafted, human-overseen. How we report
North Korean Hackers Steal $10.7M Crypto Via Fake Job Offers

The North Korean cyber group known as WaterPlum has been identified as the perpetrator behind a sophisticated phishing campaign that targeted software developers, leading to the infection of at least 30,000 devices across more than 100 countries. This operation, which ran from at least 2020 until its discovery, aimed to steal cryptocurrency, ultimately amassing approximately $10.7 million. The group employed a strategy of impersonating recruiters from legitimate companies within the cryptocurrency, artificial intelligence (AI), and non-fungible token (NFT) sectors to lure victims into downloading malicious software. These fake job offers were distributed through various channels, including professional networking sites and direct email outreach, presenting seemingly attractive employment opportunities to unsuspecting developers. Upon accepting an offer or engaging further, victims were prompted to download documents or executables that contained malware. This malware, once installed, would then grant the attackers access to the victim's systems, enabling them to steal sensitive information, including cryptocurrency wallet credentials and private keys. The scale of the operation is significant, with reports indicating that over 30,000 devices were compromised. The geographical reach of the attacks is also extensive, spanning more than 100 countries, highlighting the global nature of the threat. The financial gains reported by the group, totaling $10.7 million in stolen cryptocurrency, underscore the lucrative nature of these cybercrime operations. This campaign is part of a broader pattern of North Korean state-sponsored cyber activity, which has been increasingly focused on generating revenue through illicit means to fund the regime's activities. The group's tactics involved creating realistic-looking phishing websites and documents, often mimicking the branding and communication styles of well-known tech companies. The malware deployed was designed to be stealthy, evading detection by standard antivirus software. Analysis of the campaign revealed a multi-stage attack process, beginning with initial reconnaissance to identify potential targets and culminating in the exfiltration of cryptocurrency assets. The sophistication of WaterPlum's methods, including social engineering and advanced malware techniques, poses a significant challenge for cybersecurity professionals and individuals alike. The discovery of this operation serves as a stark reminder of the persistent threats posed by state-sponsored hacking groups and the importance of robust cybersecurity practices, particularly for individuals working in sensitive sectors like cryptocurrency and AI development. The stolen funds are believed to have been laundered through various cryptocurrency exchanges and mixers to obscure their origin and make them difficult to trace. This operation is consistent with previous reports detailing North Korea's reliance on cyber theft to circumvent international sanctions and acquire foreign currency. The group's ability to maintain such a widespread and long-running operation points to a well-resourced and organized cyber warfare unit within North Korea.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.