North Korean Hackers Steal $10.7M via Fake Job Interviews
North Korean hackers infiltrated over 30,000 devices worldwide by posing as recruiters for artificial intelligence and cryptocurrency firms, stealing at least $10.71 million from more than 7,000 crypto wallets, according to a joint advisory from Japanese and U.S. authorities. The campaign, attributed to a group known as WaterPlum, targeted software developers and IT professionals across more than 100 countries between December 2025 and July 2026. WaterPlum actors approached victims through social media, online job platforms, and freelance marketplaces, impersonating legitimate companies in the AI, crypto, and NFT sectors. They offered attractive job opportunities and then instructed candidates to download files for technical interviews or coding tests. These files contained malware, including strains such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, which allowed attackers to establish backdoors and steal sensitive information. The malware collected browser credentials, keystrokes, screenshots, private keys, and seed phrases for cryptocurrency wallets. In some cases, it also extracted identity documents like passports and drivers licenses.