Skip to content

Security1 publisher2 min readPublished

North Korea's WaterPlum fake-recruiter campaign has stolen $10.7 million from IT workers

North Korea's WaterPlum stole $10.7 million in crypto from IT workers by posing as recruiters, infecting at least 30,000 devices. The FBI is investigating a separate ShinyHunters claim that agent data left its FBIjobs recruiting site.

The Watch · Security desk

Photograph accompanying North Korea's WaterPlum fake-recruiter campaign has stolen $10.7 million from IT workers
Photo: yahoo.com

What happened

  • North Korean group WaterPlum has stolen $10.7 million in cryptocurrency from IT workers, according to The Cyber Express.
  • ShinyHunters claims it stole personal data belonging to thousands of federal agents.
  • The FBI is investigating an apparent breach, with the probe centered on its FBIjobs recruitment website.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Developers and IT workers who hold crypto and answer recruiters are WaterPlum's target set. Their interview activity now belongs in the threat model for the machines they use.
  • decision Engineering teams have to decide whether interview activity may touch machines with wallets or production access, since the interview is the campaign's delivery route.
  • constraint Until the FBI says what, if anything, left FBIjobs, affected agents cannot scope their exposure. The only size on record is the attacker's own 'thousands.'

In both cases the point of contact is a recruiting channel. WaterPlum works the candidate side. A multinational advisory exposed it as a fake-recruiter malware operation [3], and The Cyber Express describes it as a state-backed operation weaponizing job interviews against developers [7]. In the FBI case, the recruiting system itself is the reported loss. The bureau's probe centers on its FBIjobs site [5]. Beyond that shared channel, the two cases have different actors and very different levels of confirmation.

WaterPlum, also called Contagious Interview, is the sustained campaign [8]. At least 30,000 infected devices in more than 100 countries [2] is an operation run at volume. Divided across that floor, $10.7 million in stolen crypto [1] averages at most about $357 per device [1]. The figure is a ceiling because 30,000 is a minimum. Every additional infection lowers the average. The roundup does not describe the infection step or how losses are split among victims, so the average cannot show whether a few large wallets account for most of the take.

For the attacker, getting in takes a fake recruiter and a developer who replies. The targeting comes with it: the victims are IT professionals who hold cryptocurrency [1]. Stopping it costs far less. Whatever a hiring conversation asks a candidate to open or run can stay off the machine that holds wallets and work credentials.

The FBI story is at the claim stage. Public: ShinyHunters says it stole personal data belonging to thousands of federal agents [4], and the FBI is investigating what The Cyber Express calls an apparent breach [5]. Unconfirmed: whether any data left FBIjobs, and how the group got in. The Cyber Express describes ShinyHunters as a criminal group openly retaliating against the FBI over a public advisory [6].

For most operators the FBI claim changes nothing this week. It matters to the agents whose data may be in it, and to anyone running an applicant portal that stores personal data on staff in sensitive roles. The hiring-channel risk that reaches ordinary engineering teams is WaterPlum's, with at least 30,000 devices already counted [2].

What to watch

  • An FBI statement confirming or denying that data left the FBIjobs site, and how many agents it covers.
  • Technical detail from the WaterPlum advisory showing where in the interview process devices get infected.
  • Any data sample ShinyHunters publishes, which would let outsiders test the claim.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories