A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from hundreds of countries, authorities warn.
North Korean hackers steal millions in crypto heist
A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from hundreds of countries, authorities warn.
ABC News & Headlines – Australian Broadcasting Corporation
Publisher
Sep 29, 2026 at 4:54 AM UTC · 3 min de lectura
The group, known as "WaterPlum", infiltrated at least 30,000 devices stealing $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts.
Cybersecurity officials from the US, Japan, Germany and Australia issued a joint statement saying the group was targeting individual IT professionals.
What happened?
Between December 2025 and July this year, members of WaterPlum presented as an employer advertising fake roles specifically for software developers and IT professionals.
They would instruct applicants to download files for software alternatives to video conferencing apps such as Zoom to conduct interviews.
Authorities said members of the group also operated as North Korean IT workers at companies.
They would use artificial intelligence (AI) face-swapping software when beginning online interviews for roles, and then ask to disable their camera "because of network issues".
It was discovered after Japanese authorities were able to identify a "laptop farm", which obscures someone's real location, and found evidence WaterPlum had transferred millions in cryptocurrency to places outside Japan.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
