Security News

North Korean 'WaterPlum' Hackers Steal $10.5M by Posing as Recruiters

The Record · 18 Sept 2026
Key Takeaway Businesses hiring remote IT, blockchain or crypto talent should treat unsolicited recruiter contact and interview-stage file downloads with suspicion, and verify job offers through official company channels before running any software.

The FBI, US Defense Department, and law enforcement agencies in Japan, Australia and Germany have issued a joint advisory warning about WaterPlum, a North Korean-linked hacking group targeting job seekers, particularly web designers, engineers and cryptocurrency specialists. Between December 2025 and July 2026, the group infected at least 30,000 devices across 100 countries and stole funds or credentials from roughly 7,000 cryptocurrency wallets, netting more than $10.5 million.

The scheme works by contacting job seekers through social media, gig work sites and freelance portals, then posing as AI or blockchain companies. During the fake interview process, applicants are instructed to download files that secretly install malware, including strains known as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. These tools steal cryptocurrency wallet credentials and other sensitive data, and some also install remote access tools so the hackers can maintain long-term control of infected devices.

Beyond direct theft, the hackers have used stolen identity documents to gain employment elsewhere and have kept access to victim devices in hopes those individuals land jobs at other tech companies, potentially giving North Korean operatives a foothold into corporate networks. Investigators have linked WaterPlum to earlier, similar campaigns, including one uncovered in April involving fake LinkedIn recruiters targeting blockchain developers.

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.