Technology
North Korean hackers steal millions in crypto heist
Key Points
North Korean group 'WaterPlum' steals millions in crypto hack A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from hundreds of countries, authorities warn. The group, known as "WaterPlum", infiltrated at least 30,000 devices stealing $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts. Cybersecurity officials from the US, Japan, Germany and Australia issued a joint statement saying the group was targeting...
North Korean group 'WaterPlum' steals millions in crypto hack
A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from hundreds of countries, authorities warn.
The group, known as "WaterPlum", infiltrated at least 30,000 devices stealing $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts.
Cybersecurity officials from the US, Japan, Germany and Australia issued a joint statement saying the group was targeting individual IT professionals.
What happened?
Between December 2025 and July this year, members of WaterPlum presented as an employer advertising fake roles specifically for software developers and IT professionals.
They would instruct applicants to download files for software alternatives to video conferencing apps such as Zoom to conduct interviews.
Authorities said members of the group also operated as North Korean IT workers at companies.
They would use artificial intelligence (AI) face-swapping software when beginning online interviews for roles, and then ask to disable their camera "because of network issues".
It was discovered after Japanese authorities were able to identify a "laptop farm", which obscures someone's real location, and found evidence WaterPlum had transferred millions in cryptocurrency to places outside Japan.
Those who were a part of the laptop farm were often located in North Korea, China and Russia, with a small number in Africa and south-east Asia.
University of Melbourne's Andrew Cullen, who specialises in cybersecurity and AI, said these were two of the main types of scams run by the group.
He said he had seen reports of fake North Korean employees for the last three to four years but it has been accelerating.
"I don't think anybody in the West has a particularly strong grasp on exactly how long this has been happening,"Dr Cullen said.
He said it was difficult to understand the scale of the problem, especially as it related to workers infiltrating companies, because that information was rarely disclosed.
"It's really hard for governments and cybersecurity organisations to try and collect this large-scale data to show how much of a problem it is across the economy," he said.
Authorities said the group had also been able to access ID images, passwords and other sensitive data from thousands of people that could be used for extortion.
They also said the group operated under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers' Party of Korea.
What does it mean?
Dr Cullen said hacks of this nature were likely to become more prevalent because of rogue AI agents and AI tools that enable hackers to work faster with a larger scope.
According to the Royal United Services Institute (RUSI), an independent security think tank in the UK, AI was being used to speed-up the process of ransomware operations.
Dr Cullen described ransomware as when someone is locked out of their systems, and is then charged a ransom for access to their own data.
"So, instead of a hacker who is on the other side having a conversation about the extortion, that can be farmed out to an AI system," he said.
"Or an AI system can be used to help those who are doing these kind of hacks sound more natural, talk to more people, keep track of what they're doing more efficiently."
What are some countermeasures?
Dr Cullen said cybersecurity could sound big and scary, but there were simple principles that could help protect someone's data and security.
These included changing passwords regularly, keeping devices updated, and avoiding suspicious links and software.
He also said employers should meet physically with remote staff to verify their identities.
"These are all the basic cybersecurity messages that we've had for the last 10 years,"he said.
Dr Cullen said this was because hackers had not improved but the volume and speed of them have increased.
Outside of increasing funding to cybersecurity, Dr Cullen said governments could also set rules that made hacking people in Australia less attractive.
He highlighted setting specific legislation that stopped companies paying bribes to ransomware groups.
"So there's a real job for the government to make sure they're setting the legislation so that Australians aren't targeted," he said.
[Image text:] 19602204222782122240 30781 19510 246
1982123912761199239171695719337824847157092386027158 7723 2097426128 32021 22711 2122912142 8499
52613472378725121247131874713138124711970393727024 29914 1878367081087526495174986597
02787653126101127348 12244 15355 1883315474 12434 201838521 2723 13105 1424927660535926067 30577 1661
2471 1622921725 145691717421286 2640726948 18974 408327513243932146 3082715237309831094468551211
4197 298832305201 5370 1771027692 5776 9918 16340 28831 8012 2881317
6602 32077 25669 28808 26414 21535 28946 11156 20977 32607 28399 27749
33736623141196055 1491 87605755890612
24873.2012224