September 22, 2026, 7:44 am | Read time: 3 minutes
North Korean cybercriminals are alleged to have compromised thousands of computers worldwide through fake job offers. According to investigators, the group WaterPlum used this tactic over several months to install malware on their victims’ devices. Users in more than 100 countries, including Germany, were affected.
Due to the attacks, the FBI and security agencies from Japan, Germany, and Australia have issued an international warning. Investigators report that the group infected more than 30,000 computers between December 2025 and July 2026, stealing cryptocurrencies worth over 9 million euros.
Hackers Disguised as Recruiters
For their attacks, the perpetrators used social networks and job platforms. They posed as recruiters from tech companies and specifically targeted web designers, software developers, and specialists in cryptocurrencies, blockchain, and Web3.
Interested parties received supposed job offers and were involved in a fake application process. They were asked to complete technical tasks or correct errors in program code. However, the files provided contained malware. Programs mentioned include BeaverTail, InvisibleFerret, and OtterCookie.
The programs can be executed on both Windows and macOS devices. After a successful infection, the attackers could permanently access the affected computers and extract information such as passwords, keystrokes, or data from crypto wallets.
More Than 7,000 Crypto Accounts Affected
According to authorities, more than 7,000 cryptocurrency accounts were compromised. The stolen amount is said to be at least $10.7 million, or approximately 9.3 million euros.
Additionally, the perpetrators reportedly used AI software in some cases to manipulate faces during video interviews, aiming to deceive more individuals.
Authorities advise against running program code of unknown origin directly on one’s computer. Instead, secure virtual environments should be used. If there is suspicion of an infection, the device’s internet connection should be immediately disconnected.
Manipulated Games on Steam Infected Thousands of Computers
Germany Suffers More Hacker Attacks Than Any Other EU Country
Fraudsters Repeatedly Use Similar Methods
The theft of cryptocurrencies has been a method used by many cybercriminals for years. Fraudsters attempt to gain access to digital wallets in various ways. They often use social networks to build trust and specifically target their victims.
Also of interest: After the hacker attack on Berlin – how users should respond
Therefore, it remains important not to respond to suspicious messages. In case of doubt, experts recommend contacting the relevant authorities.
Connection to North Korean Agency
The FBI links WaterPlum to the 313 General Bureau of the Munitions Industry Department, a North Korean agency for weapons development and IT strategy.
Investigators believe the stolen funds could be funneled into weapons programs. The group reportedly received support in Japan, where helpers provided computers, servers, and bank accounts. The Japanese police have announced that the network has since been dismantled.
Experts also estimate that around 100,000 North Korean IT workers are operating worldwide under false identities, potentially bringing in up to $500 million annually for the regime.