North Korea-linked hackers from the WaterPlum group infect at least 30,000 devices worldwide by posing as tech recruiters and tricking developers into downloading malware, according to multiple reports. The attackers target people working in or connected to the technology and cryptocurrency sectors, using fraudulent job outreach to deliver malicious software.
The malware activity is reported to span more than 100 countries. One outlet says the theft includes compromising funds from more than 7,000 cryptocurrency wallets, while another reports a larger aggregated theft figure of about $10.7 million and describes the campaign as targeting developers with fake roles at crypto, AI, and NFT companies.
While both accounts agree on the use of recruiter-themed social engineering, the reported scale and characterization of the stolen funds vary: figures differ between the number of wallets reportedly affected and the total dollar value provided. The overarching details—WaterPlum, fake recruitment lures, device infections, and financial theft from crypto—remain consistent across the coverage.