ChainCatcher reported that the North Korean hacking group WaterPlum posed as recruiters from cryptocurrency, AI, and NFT companies and sent malware to software developers and IT workers. The malicious files were disguised as coding assignments or fixes for video meeting software. According to the report, the group infected at least 30,000 devices across more than 100 countries. It also extracted funds or account credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The total amount stolen was at least $10.7 million. The report points to a targeted social engineering campaign aimed at people working in technical roles, with the malware distributed under the cover of job-related communication and work tasks.
According to ChainCatcher, the North Korean hacking group WaterPlum posed as recruiters from cryptocurrency, AI, and NFT companies to deliver malware to software developers and IT workers.
The malware was disguised as coding assignments or files presented as fixes for video meetings. ChainCatcher said the group infected at least 30,000 devices in more than 100 countries and, between December 2025 and July 2026, extracted funds or account credentials from more than 7,000 cryptocurrency wallets. The amount stolen was at least $10.7 million.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.