The North Korean hacker group WaterPlum pulled off a massive campaign targeting developers by pretending to be recruiters from crypto, AI, and NFT companies. The attack infected at least 30,000 devices across more than 100 countries, racking up $10.7 million in stolen crypto.
Who They Targeted and How
According to reports, WaterPlum went after developers, luring them with job offers at crypto, AI, and NFT firms. These fake job postings and recruiter chats were just bait to get victims to compromise their own devices.
Scale and Damage
At least 30,000 devices worldwide got hit—spanning over 100 countries. The direct losses in crypto hit $10.7 million. The sheer geographic spread and number of compromised machines show how systematic and long-running this attack really was.
How to Stay Safe
If you're a developer or on a dev team, be skeptical of any job offers: double-check company domains and communication channels, never open sketchy files or links, and use separate work environments for anything external. For accounts and crypto assets, enable multi-factor authentication and use hardware keys. Limit workstation access to only what's absolutely necessary, and keep your software up to date.
