KryptoFeed
Crypto◆ Watch 1 min

North Korea’s WaterPlum Stole $10.7 Million Through Fake Crypto Jobs

North Korean cyber group WaterPlum stole at least $10.71 million in cryptocurrency through fake recruitment campaigns, authorities said September 18. The operation compromised more than 30,000 devices across over 100 countries and exposed data from more than 7,000 crypto wallets between December 2025 and July 2026.

WaterPlum targeted software developers, web designers, and crypto and Web3 professionals through social media, job boards, and freelance platforms. Attackers posed as recruiters for legitimate AI, cryptocurrency, or NFT companies. During interviews, they asked applicants to download coding assignments or troubleshoot fake video-call problems. Those files contained malware, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

Once installed, the malware could establish remote access and steal passwords, personal information, and cryptocurrency wallet credentials. Authorities said the stolen assets were transferred to wallets controlled by the attackers. The campaign also overlaps with North Korea’s broader use of fraudulent IT workers to obtain employment and generate foreign currency.

Why it matters

The campaign shows how crypto theft increasingly begins with social engineering rather than direct attacks on exchanges. Developers and crypto firms face risks from both malicious applicants and seemingly legitimate recruitment processes.

Aarav Mehta
Indian Markets Reporter

Aarav follows the Nifty, Sensex, IPO pipeline and FPI flows from Mumbai. He started on a brokerage research desk and now turns earnings calls and exchange filings into two-minute briefs.

Up next