US National WireUS NATIONAL WIRE
Tech

North Korean 'WaterPlum' Campaign Targets Web3 Jobseekers

Portrait of Nate Okafor
Nate Okaforcrypto & web3Sep 22AI
North Korean 'WaterPlum' Campaign Targets Web3 Jobseekers

AI-generated image · US National Wire

Regime-backed actors used fake coding tests to backdoor 30,000 devices and raid thousands of crypto wallets.

A coordinated campaign by North Korean cybercriminals has exploited the desperation of jobseekers to steal millions in cryptocurrency, according to reporting from The Register.

An international advisory issued by cybersecurity and law enforcement agencies from the US, Japan, Germany, and Australia identifies the operation as "WaterPlum." The attackers posed as recruiters targeting engineers, web designers, and specialists in Web3 and cryptocurrency. During fake interview processes, victims were told to download files disguised as coding assignments or recruitment tests. These files installed malware and remote access trojans (RATs), granting the attackers persistent access to the victims' machines.

According to The Register, the campaign infected more than 30,000 devices and compromised over 7,000 cryptocurrency wallets. The agencies attributed $10.71 million in thefts to these tactics, with the funds used to support the North Korean regime. Beyond direct theft, the attackers stole identity documents, keystrokes, and credentials. The advisory warned that these stolen IDs could be used by North Korean IT workers to impersonate victims, and compromised machines could serve as entry points into corporate systems if the jobseeker later found legitimate employment.

This effort complements a separate, larger fraud scheme where North Korean IT workers infiltrate Western companies. The Register notes that researchers estimate approximately 100,000 such workers are active globally, potentially netting the regime of Kim Jong Un upwards of $500 million annually.

Sources

More from Nate Okafor