WaterPlum Used Fake Crypto Jobs to Breach 30,000 Devices

WaterPlum Used Fake Crypto Jobs to Breach 30,000 Devices

By: WEEX|2026/09/20 01:52:02

WEEX View

  1. The near-term issue for exchanges, wallet providers and employers is whether additional WaterPlum-linked addresses, malware indicators or compromised hiring channels are publicly identified. That would shape screening, account monitoring and incident response across the crypto stack.
  2. The case also puts renewed focus on developer-side security. The campaign targeted people likely to run code, test repositories or open project files, making recruitment workflows and technical interview materials a direct attack surface for crypto firms.
  3. Another point to watch is whether authorities disclose more detail on how stolen assets moved on-chain and where they touched centralized platforms. That could affect sanctions compliance, wallet risk controls and fund tracing efforts.

A joint advisory from authorities in Japan, the U.S., Australia and Germany said North Korean-linked cyber actor WaterPlum infected at least 30,000 devices in more than 100 countries from around December 2025 through July 2026, using fake job offers tied to AI, cryptocurrency and NFT companies to steal funds or credentials from more than 7,000 crypto wallets.

The advisory said WaterPlum approached job seekers on social media, recruitment sites and freelance platforms while posing as legitimate employers. Victims were lured into downloading malicious files presented as coding tests, interview assignments or development projects. The primary targets were web designers, engineers and specialists working in cryptocurrency, blockchain and Web3.

Authorities said the operation infected at least 30,000 PCs across more than 100 countries, including Japan and the United States. The actors exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets and transferred at least 1.7 billion Japanese yen, or about $10.71 million, in crypto assets on behalf of North Korea.

The same advisory assessed that WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers' Party of Korea. Investigators also linked the campaign to the activity commonly referred to as “Contagious Interview,” a social-engineering pattern in which attackers impersonate recruiters and push malware through supposed hiring processes.

Authorities and security researchers have previously described similar operations aimed at Web3 developers, including campaigns that used fake recruiting outreach, malicious code repositories and infected technical tests. In WaterPlum’s case, the reported scale suggests a broad theft pipeline rather than a small number of highly targeted intrusions.

Why It Matters

The case highlights how crypto theft is increasingly tied to attacks on people who sit close to code, wallets and infrastructure rather than only on exchanges or protocols themselves. Hiring channels, freelance marketplaces and developer collaboration tools are becoming part of the threat surface for digital asset firms.

It also underscores the compliance dimension of DPRK-linked crypto crime. Once stolen funds move through wallets, bridges or centralized venues, exchanges and service providers may face greater pressure to strengthen address screening, transaction monitoring and internal controls around sanctioned or high-risk counterparties.

Milestones

2026/04/24
2026/05/09
2026/07/26
Security firm Expel said a North Korean-backed group known as HexagonalRodent was targeting Web3 developers with fake job offers and malicious skills tests.
Researchers disclosed a Lazarus-linked “infectious interviews” tactic that used fake crypto and DeFi hiring processes to deliver malicious code repositories.
BlueNoroff was reported to be using fake Zoom and Microsoft Teams meeting links to target crypto users with malware, extending the same social-engineering pattern.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

About WEEX View

WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com