NewsDialy
A North Korean cyber group called WaterPlum stole $10.7 million in cryptocurrency by luring developers with fake job offers. The attack infected at least 30,000 devices across more than 100 countries.
In plain terms, this was a large-scale social engineering campaign where the initial trick was a job interview, not a technical exploit.
The fake recruiter method The operation targeted software developers working in the crypto, AI, and NFT sectors. WaterPlum posed as recruiters for these companies.
They offered jobs that appeared legitimate to draw in applicants. Once a developer engaged with the fake recruiter, the group installed malicious software on the victim's computer.
Keep reading