North Korea-linked hackers net $10.71 million via fake tech recruiting scheme targeting developers

AI Market Summary
A joint FBI and Japan NPA warning details North Korea-linked WaterPlum using fake AI/crypto/NFT job interviews to deploy malware, infecting 30,000+ devices and compromising 7,000+ crypto wallets, with at least $10.71M stolen. The scale of social-engineering driven wallet drains heightens operational risk for retail and developer communities, potentially tightening security posture and dampening near-term risk appetite across liquid crypto assets.
Impact level
● Medium
Affected assets
BTC/USDT-1.11%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Odaily Planet Daily reports that a coalition of international law enforcement agencies, including the U.S. Federal Bureau of Investigation and Japan's National Police Agency, has issued a joint alert on a North Korea-linked hacking group known as WaterPlum, also called Contagious Interview. Authorities say the group targeted IT developers worldwide from December 2025 through July 2026 by posing as companies in the AI, cryptocurrency and NFT sectors. Investigators say attackers approached job seekers through social media and recruitment platforms, then lured them into downloading malicious files disguised as materials for technical interviews or coding tests. More than 30,000 devices across over 100 countries and regions were infected. The campaign is believed to have compromised data from more than 7,000 cryptocurrency wallets, with at least $10.71 million transferred to wallets controlled by the attackers.