A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from hundreds of countries, authorities warn.
The group, known as “WaterPlum”, infiltrated at least 30,000 devices stealing $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts.
Cybersecurity officials from the US, Japan, Germany and Australia issued a joint statement saying the group was targeting individual IT professionals.
What happened?
Between December 2025 and July this year, members of WaterPlum presented as an employer advertising fake roles specifically for software developers and IT professionals.
They would instruct applicants to download files for software alternatives to video conferencing apps…






