North Korean hacking group WaterPlum allegedly posed as recruiters for cryptocurrency, AI and NFT companies to distribute malware to software developers and IT workers. The malicious files were disguised as coding assignments or fixes for video meeting issues. According to the report, the campaign infected at least 30,000 devices across more than 100 countries. Cointelegraph said the group extracted funds or account credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The total amount stolen was at least $10.7 million. The case points to a broad social engineering operation aimed at people working in technical roles tied to the digital asset sector.
North Korean hacking group WaterPlum allegedly posed as recruiters for cryptocurrency, AI and NFT companies and sent malware to software developers and IT workers.
The malicious files were disguised as coding assignments or as fixes for video meeting problems. The operation infected at least 30,000 devices in more than 100 countries, according to the report.
Cointelegraph reported that between December 2025 and July 2026, WaterPlum extracted funds or account credentials from more than 7,000 cryptocurrency wallets, stealing at least $10.7 million.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.