CYBERSECURITYTRACKER
TRACKING7,184 stories in this site build1,511 vulnerability news stories in this site build
Permanent story citation

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7782

As cited

Copy frozen at (site build).

government policy

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

U.S. and allied security agencies have identified WaterPlum, a North Korean hacking group subordinate to the Munitions Industry Department, as targeting job seekers worldwide by posing as recruiters for artificial intelligence, cryptocurrency, and other firms. The group has infected over 30,000 devices across more than 100 countries and stolen approximately $11 million in cryptocurrency from 7,000 crypto wallets. Agencies in Japan, Australia, Germany, and the U.S. have begun dismantling infrastructure, including a laptop farm in Japan, and are coordinating further enforcement efforts.

Why it matters: Software developers, IT professionals, and cryptocurrency users need to scrutinize unsolicited job offers and avoid downloading files from unknown recruiters, as this campaign directly targets technical staff with financial and credential theft as the objective.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

government policy

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

U.S. and allied security agencies have identified WaterPlum, a North Korean hacking group subordinate to the Munitions Industry Department, as targeting job seekers worldwide by posing as recruiters for artificial intelligence, cryptocurrency, and other firms. The group has infected over 30,000 devices across more than 100 countries and stolen approximately $11 million in cryptocurrency from 7,000 crypto wallets. Agencies in Japan, Australia, Germany, and the U.S. have begun dismantling infrastructure, including a laptop farm in Japan, and are coordinating further enforcement efforts.

Why it matters: Software developers, IT professionals, and cryptocurrency users need to scrutinize unsolicited job offers and avoid downloading files from unknown recruiters, as this campaign directly targets technical staff with financial and credential theft as the objective.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

government policy

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

U.S. and allied security agencies have identified WaterPlum, a North Korean hacking group subordinate to the Munitions Industry Department, as targeting job seekers worldwide by posing as recruiters for artificial intelligence, cryptocurrency, and other firms. The group has infected over 30,000 devices across more than 100 countries and stolen approximately $11 million in cryptocurrency from 7,000 crypto wallets. Agencies in Japan, Australia, Germany, and the U.S. have begun dismantling infrastructure, including a laptop farm in Japan, and are coordinating further enforcement efforts.

Why it matters: Software developers, IT professionals, and cryptocurrency users need to scrutinize unsolicited job offers and avoid downloading files from unknown recruiters, as this campaign directly targets technical staff with financial and credential theft as the objective.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary