North Korean cyber group WaterPlum has successfully infected at least 30,000 devices across more than 100 countries. The group achieved this by targeting developers with deceptive job opportunities, specifically focusing on individuals working within crypto, AI, and NFT companies. By luring them with attractive but fraudulent employment offers, WaterPlum managed to gain access to a vast number of systems globally through this sophisticated operation.
Through these widespread infections, WaterPlum was able to steal a significant sum totaling $10.7 million in cryptocurrency. The method involved presenting fake positions at prominent companies in emerging technology sectors. This tactic proved highly effective in compromising a substantial number of target devices and securing considerable financial gains for the cyber group.