North Korean Group WaterPlum Steals $10.7M via Fake Recruitment
- WaterPlum, a North Korean hacking group, stole at least $10.7 million by posing as recruiters for legitimate crypto and AI companies.
- The group infected over 30,000 devices across more than 100 countries, targeting software developers and IT professionals.
- From December to July, they extracted funds or credentials from over 7,000 cryptocurrency wallets.
- Victims were tricked into downloading malware disguised as coding assignments or video-conferencing fixes.
- The advisory links WaterPlum to North Korea’s Munitions Industry Department and their broader campaign of infiltrating foreign companies.
This incident highlights the ongoing threat posed by state-sponsored cybercrime, particularly in the crypto sector, where North Korea has been increasingly active in thefts to fund its operations.
The reported theft of $10.7 million underscores the vulnerabilities within the industry as malicious actors exploit recruitment processes to gain access to sensitive information and assets.(Source)