← BACK TO FEED
TAG

crypto theft2 articles

North Korea's Fake Recruiters Have Infected 30,000 Devices and Counting

North Korea-linked cybercriminals, tracked as WaterPlum, have infected over 30,000 devices and stolen more than $10 million by posing as job recruiters and tricking applicants into downloading malware disguised as coding tests or recruitment materials. Once installed, the malware gives attackers persistent access to credentials, cryptocurrency wallets, and sensitive data, with proceeds funnelled to the North Korean regime. This scheme complements North Korea's broader strategy of placing fraudulent IT workers inside Western companies, an operation estimated to generate over $500 million annually for Pyongyang.

20 Sept 2026

ClickFix Malware Can Slowly Bleed Your Crypto Wallet Dry

ClickFix-style attacks are being used to deliver a Go-based macOS malware that steals browser passwords, Apple Keychain data, and cryptocurrency wallet contents, with the ability to gradually drain funds across multiple cryptocurrencies including Bitcoin, Ethereum, and Monero. The attack tricks victims into pasting a command into Terminal, which profiles the system, downloads a compatible payload, and uses a fake error prompt to harvest system credentials. The malicious infrastructure is linked to Aeza Group, a Russian bulletproof hosting provider sanctioned by the US, UK, and Australia.

8 Aug 2026