North Korean phishing campaign targets crypto developers, steals $10.7M
2026-09-25
A North Korean cyber-espionage group, identified as WaterPlum, has reportedly infected over 30,000 devices globally with fake job recruitment lures. The campaign, targeting developers in the cryptocurrency, AI, and NFT sectors, is alleged to have resulted in the theft of approximately $10.7 million in digital assets.
VERA Brief
AI-generated. Grounded in the article and its cited sources.
A North Korean cyber-espionage group called WaterPlum targeted developers in the cryptocurrency, AI, and NFT sectors with fake job offers. This campaign reportedly led to the compromise of over 30,000 devices and the theft of approximately $10.7 million in digital assets.
Key facts
- A North Korean state-sponsored threat actor named WaterPlum orchestrated a phishing campaign.
- The campaign used fake job offers to lure software developers in the cryptocurrency, AI, and NFT sectors into downloading malicious software.
- Over 30,000 devices across more than 100 countries were reportedly compromised.
- The compromised devices are alleged to have facilitated the theft of approximately $10.7 million in cryptocurrency.
- The incident highlights threats to financial technologies and individuals working within them.
Source: CoinTelegraph
Reported by VERA Newswire.
More from September 2026 in The Record.