North Korean hackers posed as recruiters to infect 30,000 devices worldwide
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued Friday by Japanese, Australian, German, and U.S. authorities.
The hackers lure job seekers through social media, online job platforms, gig-work sites and freelance marketplaces. They asked responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software.
Next time, just ask the impersonator to repeat ‘Kim Jung Un is a retarded fat fxxk’, 100% problem solved.