North Korean WaterPlum hackers infected 30,000 devices worldwide
- On Sept 18, Japan's National Police Agency and international partners including the FBI released findings uncovering the hacking group WaterPlum's methods, revealing direct links between its cyberattacks and North Korean IT worker operations under Bureau 313.
- The hacking group has compromised more than 30,000 devices across over 100 countries, stealing data from more than 7,000 cryptocurrency wallets after targeting developers through fake recruitment campaigns and malicious software like BeaverTail and InvisibleFerret.
- Associated with the 'Contagious Interview' threat, North Korean workers operate under Bureau 313, often resisting relocation while using VPN services to conceal their true locations during technical interviews.
- The Justice Department recently led enforcement efforts involving more than $7.74 million in digital assets, while two men received 18 month prison sentences in 2026 for assisting North Korean workers in accessing company laptops.
- Authorities urge employers to scrutinize candidates by verifying technical skills and ensuring stated residences match IP addresses, particularly when applicants resist relocation or demand cryptocurrency payments.
74 Articles
74 Articles
North Korean Hackers Infect 30,000 PCs, Steal $10,700,000 in Crypto Through Fake IT Jobs: FBI
A North Korean state-sponsored group known as WaterPlum is targeting IT professionals worldwide with fake job offers that deliver malware to steal cryptocurrency and financial data.
North Korean hackers scam IT job seekers, steal Rs 100 crore
A North Korean hacking group called WaterPlum scammed IT job seekers worldwide. The group gained access to 30,000 devices by sending malicious files to job seekers and stole roughly Rs 100 crore in cryptocurrency.
Hackers use fake coding tests to infect 30,000 devices and steal $10 million in crypto
The agencies refer to the group behind the activity as WaterPlum. It targets web designers, software engineers and people working in cryptocurrency and Web3. The group contacts victims while posing as recruiters, then sends what appears to be a coding exercise or other technical test as part of the hiring...Read Entire Article
North Korean Fake Recruiters Steal $10.7M in Crypto
North Korea-linked WaterPlum infected at least 30,000 devices in 100 countries and compromised over 7,000 crypto wallets through fake job interviews.
FBI Warns US IT Workers as North Korean Hackers 'WaterPlum' Use AI Face Swaps in $10.7M Fake Job Scam
The FBI and international partners say WaterPlum targeted technology workers through fraudulent recruitment, infecting at least 30,000 devices and transferring $10.71 million in cryptocurrency to North Korea.
Coverage Details
Bias Distribution
- 58% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

























