North Korea's WaterPlum, a state-backed hacking group, stole $10.7 million through an elaborate fake recruitment scheme, according to reports from Japan's National Police Agency and the U.S. Federal Bureau of Investigation.
The group impersonated hiring managers for cryptocurrency firms, NFT businesses, and artificial intelligence companies, targeting IT and software developers. Victims were directed to take fake skill assessments that actually deployed malicious programs designed to drain their cryptocurrency wallets.
According to the report, WaterPlum infiltrated approximately 30,000 devices across more than 100 countries, compromising over 7,000 crypto wallets during an eight-month period. In a separate tactic, the group also posed as employees to secure positions with crypto firms, gaining access to company systems for further compromise.
Broader North Korean Threat
WaterPlum represents one of several North Korean state-backed hacking operations targeting the cryptocurrency industry. Other notable groups include AppleJesus, also tracked as Citrine Sleet or UNC4736, which was linked to a $285 million exploit of the Drift protocol involving an extensive six-month social engineering campaign. The Lazarus Group, another state-backed actor, has been attributed to the $1.5 billion Bybit exchange heist and a $292 million KelpDAO exploit.
Security firms report that stolen cryptocurrency has become a significant revenue stream for North Korea. In 2025, North Korean threat actors accounted for 60 percent of $3.4 billion in annual crypto losses, or approximately $2 billion. As of the second half of 2026, North Korea-based hackers have accounted for 76 percent of total crypto losses, amounting to over $600 million.


