A cyber campaign linked to North Korea reached at least 30,000 devices across more than 100 countries. To find victims, criminals created fake job opportunities in the crypto, artificial intelligence, blockchain, and non-fungible tokens (NFTs) sectors.
Known as WaterPlum or Contagious Interview, the group used fraudulent hiring processes to install malicious programs on candidates’ computers. According to a joint alert from international authorities, the attacks resulted in the diversion of about US$10.71 million in cryptocurrency.
Authorities also identified the withdrawal of funds or credentials from more than 7,000 wallets between December 2025 and July 2026. Developers, engineers, freelancers, and Web3 professionals were among the main targets of the operation.
The fake North Korean recruiters approached professionals via social media, job sites, freelance platforms, and temporary work services. They then offered positions allegedly provided by well-known companies or businesses linked to crypto, AI, and NFTs.
#Criptomoedas #Technology