North Korean 'WaterPlum' Hackers Steal $10.5M by Posing as Recruiters
The FBI, US Defense Department, and law enforcement agencies in Japan, Australia and Germany have issued a joint advisory warning about WaterPlum, a North Korean-linked hacking group targeting job seekers, particularly web designers, engineers and cryptocurrency specialists. Between December 2025 and July 2026, the group infected at least 30,000 devices across 100 countries and stole funds or credentials from roughly 7,000 cryptocurrency wallets, netting more than $10.5 million.
The scheme works by contacting job seekers through social media, gig work sites and freelance portals, then posing as AI or blockchain companies. During the fake interview process, applicants are instructed to download files that secretly install malware, including strains known as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. These tools steal cryptocurrency wallet credentials and other sensitive data, and some also install remote access tools so the hackers can maintain long-term control of infected devices.
Beyond direct theft, the hackers have used stolen identity documents to gain employment elsewhere and have kept access to victim devices in hopes those individuals land jobs at other tech companies, potentially giving North Korean operatives a foothold into corporate networks. Investigators have linked WaterPlum to earlier, similar campaigns, including one uncovered in April involving fake LinkedIn recruiters targeting blockchain developers.