North Korean Hacking Group Stole Millions in Crypto
International agencies identified a campaign that compromised 30,000 devices between December 2025 and July 2026.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust that current remote hiring processes effectively verify the identity of all job applicants?
Between December 2025 and July 2026, the North Korean hacking group WaterPlum compromised 30,000 devices across 100 countries. The operation resulted in the theft of $10.7 million in cryptocurrency, which authorities say was used to finance North Korean military programs.
Why it matters
The campaign highlights the sophisticated methods North Korean state-linked actors use to fund military initiatives through cyber warfare. By posing as recruiters in the tech sector, operators were able to infiltrate high-value networks and steal assets on a global scale.
The WaterPlum campaign utilized a diverse suite of malware, including JavaScript loaders, Python backdoors, and information-stealing trojans. Attackers further enhanced their success by using AI-powered face-swapping tools during video-conferencing interviews.
The players
WaterPlum
This North Korean hacking group operates as a tool for illicit state revenue generation and espionage.
313 General Bureau
This North Korean entity oversees the state-linked cyber operations that fund military development.
The details
Operators impersonated recruiters for AI, NFT, and cryptocurrency firms to deliver malware through fake coding tests or sham interviews. Japanese authorities later dismantled a domestic laptop farm that the group used to support the operation, which is reportedly linked to the North Korean 313 General Bureau.
Timeline
The campaign compromised 30,000 devices between December 2025 and July 2026.
International agencies released a joint security advisory in mid-September 2026.
The Tech Race
The WaterPlum operation represents a significant evolution in social engineering, moving beyond simple phishing to advanced AI-assisted identity theft. This trend signals a persistent shift toward using high-tech deception to bypass traditional security protocols in the remote work era.
Users in the tech industry should verify recruiter identities through official portals rather than relying solely on video calls. Increased vigilance regarding coding tests or file-sharing links during remote hiring processes is essential to avoid potential malware infection.
The takeaway
The WaterPlum campaign demonstrates that cyber criminals are increasingly weaponizing AI tools to manipulate the remote hiring process. Individuals should treat unsolicited job opportunities from unknown platforms with extreme caution to protect their devices and personal credentials.
Further reading
For more information on current digital threats, visit our Cybersecurity section.
Live Poll
Do you trust that current remote hiring processes effectively verify the identity of all job applicants?







