security · Security · North Korea · Social engineering

Fake Recruiters Stole $10.7M in Crypto

A joint government advisory linked North Korea's WaterPlum campaign to fake recruiting approaches that infected at least 30,000 devices in more than 100 countries and extracted funds or credentials from over 7,000 wallets.

Observed September 21, 2026 at 9:50 AMBlue Rogues Newsroom
Fake Recruiters Stole $10.7M in Crypto — Blue Rogues Crypto editorial artwork
Blue Rogues editorial artwork · BRC-20260921-003

Developers were targeted with malicious coding tests and fake video-conference fixes. Treat unsolicited job files as hostile until independently verified.

What is confirmed

The approved source supports the factual core above within the stated observation window. Blue Rogues preserves the source attribution and does not extend the evidence beyond what was reported.

What it does not confirm

Developers were targeted with malicious coding tests and fake video-conference fixes. Treat unsolicited job files as hostile until independently verified.

Sources and disclosures

Source: Cointelegraph — North Korean fake recruiters infect 30,000 devices. Facts remain attributed where the underlying evidence is reported rather than independently reproduced by Blue Rogues.

Update note

Observed September 21, 2026 during the approximately 09:20–09:50 BRT editorial window. Time-sensitive figures are preserved as that point-in-time snapshot.