North Korean Hackers Infect 30,000+ PCs Using Fake IT Job Interviews

A North Korean-linked hacking group called 'Water Plum' has infected over 30,000 computers across more than 100 countries between December 2025 and July 2026, stealing funds or account information from over 7,000 cryptocurrency wallets, according to reports. The Australian Cyber Security Centre, along with Japan's National Police Agency, the U.S. FBI and Defense Department Cybercrime Center, and German intelligence agencies, issued a joint advisory stating that Water Plum lured victims through fake job postings and online interviews. Hackers instructed applicants to download and execute malicious files under the guise of coding tasks or resolving video conference issues. The advisory noted that Water Plum targeted web designers, engineers, and professionals in virtual asset, blockchain, and Web3 technology fields.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: 북한 해커, 가짜 IT 면접으로 PC 3만대 감염