Techno Time

Global Security Agencies Warn of North Korean Hackers ”WaterPlum” Targeting Tech Job Seekers

Thursday 24 September 2026 08:35
Global Security Agencies Warn of North Korean Hackers ”WaterPlum” Targeting Tech Job Seekers

International security agencies have issued a stark warning regarding a massive cyber espionage campaign orchestrated by the North Korean hacking group 'WaterPlum'. The group is actively impersonating recruiters and companies within the cryptocurrency, artificial intelligence (AI), and NFT sectors to target tech professionals and job seekers.

The hackers utilize seemingly legitimate job offers to lure victims into fake job interviews and coding assessments. Candidates are subsequently instructed to download files or execute code repositories containing malware. This malicious software enables the attackers to compromise devices and siphon sensitive data, including credentials linked to cryptocurrency wallets.

According to a joint advisory released by security authorities in the United States, Japan, Australia, and Germany, WaterPlum's operations infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026.

The attackers successfully breached funds or account data associated with over 7,000 crypto wallets, funneling approximately 1.7 billion Japanese yen (equivalent to $10.71 million) in crypto assets back to North Korea.

**Exploiting the Hiring Process**
The campaign predominantly targets software developers, web engineers, and specialists in cryptocurrency, blockchain, and Web3. These fraudulent job listings are widely disseminated across recruitment platforms, freelance networks, and social media channels.

The operation relies heavily on exploiting the inherent trust within the hiring process. By masquerading as legitimate recruiters and deploying standard recruitment procedures—such as interviews and technical tests—the attackers establish a convincing facade to infiltrate victims' hardware and extract highly sensitive information.

This sophisticated tactic serves as a critical alert for tech professionals. Cybersecurity experts urge candidates to strictly avoid interacting with external files, code snippets, or software tools sent during recruitment processes without independently verifying the identity of the company and the individuals behind the offer.