A North Korean cyber group called WaterPlum stole $10.7 million in cryptocurrency by luring developers with fake job offers. The attack infected at least 30,000 devices across more than 100 countries. In plain terms, this was a large-scale social engineering campaign where the initial trick was a job interview, not a technical exploit.
The fake recruiter method
The operation targeted software developers working in the crypto, AI, and NFT sectors. WaterPlum posed as recruiters for these companies. They offered jobs that appeared legitimate to draw in applicants. Once a developer engaged with the fake recruiter, the group installed malicious software on the victim's computer. This allowed the attackers to access the user's digital assets. The scale of the operation was significant, with devices compromised on every continent.
Here is what that means for the broader threat landscape. It is not a simple virus that spreads through email links. It is a human-centric attack. The victims were likely skilled professionals who trusted the professional context of a job offer. The attackers leveraged that trust to gain access to sensitive information. The $10.7 million figure represents the direct financial loss from the stolen cryptocurrency. It highlights the value that cybercriminals place on accessing individual developer wallets and keys.
The scope of the infection
The number of infected devices reached 30,000. The geographic spread covered more than 100 countries. This indicates a global targeting strategy rather than a localized one. The group did not focus on a single industry but cast a wide net across the tech sector. The specific sectors mentioned are crypto, AI, and NFTs. These are areas where high-value digital assets are common. By targeting developers in these fields, WaterPlum aimed for high-reward victims. The infection count suggests that many of these fake job offers were successful in delivering the malicious payload.
The operation demonstrates a shift in how state-linked groups conduct financial theft. Instead of attacking a central exchange or a large corporation, they go after the individual. The developer is the weak link in the security chain. By compromising the person, the attackers bypass many of the institutional safeguards that protect the companies they pretend to represent. The $10.7 million loss is a concrete example of the cost of this human-targeting approach. It is a reminder that job security is no longer just about salary and benefits. It is also about the digital security of the applicant.