North Korean WaterPlum Hackers Infected 30,000 Devices and Stole $10.7 Million in Crypto
A joint law enforcement advisory warns that the North Korean hacker group WaterPlum compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026. The attackers also transferred more than $10.7 million in stolen cryptocurrency to North Korea.
The findings come from joint recommendations issued by Japanese, U.S., Australian, and German authorities, which collectively tracked the threat group’s activities.
WaterPlum targets job seekers with fake interviews
WaterPlum is associated with a multiyear campaign known as “Contagious Interview.” The campaign has previously targeted job seekers with malicious npm packages that infect their devices with malware.
Attackers impersonate legitimate artificial intelligence, cryptocurrency, and NFT companies, or contact victims through recruitment and freelance platforms.
During fake interviews and coding tests, victims may be instructed to download software projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

WaterPlum stole cryptocurrency and account credentials
WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and fund its weapons programs.
“WaterPlum attackers infected at least 30,000 devices in over 100 countries and stole funds and account credentials from over 7,000 crypto wallets.” Read the advisory.
According to the advisory, WaterPlum officials transferred 1.7 billion yen, equivalent to $10.71 million, in crypto assets to the Democratic People’s Republic of Korea, or North Korea.
Malware linked to WaterPlum operations
The advisory associates several malware families with WaterPlum operations:
- BeaverTail: JavaScript malware hidden in npm packages.
- Invisible Ferret: A Python-based backdoor.
- OtterCookie: A JavaScript remote-access trojan and information stealer.
- OtterCandy: Malware that combines the functionality of OtterCookie and a remote-access trojan.
- Ermine Waffle: Modular Node.js malware delivered through a malicious Visual Studio Code project. A configuration file executes code after the folder is opened and trusted.
Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys, seed phrases, and documents. The malware can also capture screenshots.
Attackers may use access to infected computers to enter employer or customer networks, potentially expanding their operations to intellectual property theft and espionage.
North Korean IT workers linked to WaterPlum
The agencies directly linked WaterPlum to rogue North Korean IT workers. Investigators said some WaterPlum hackers also worked as remote IT workers performing web development for clients, and that the two groups used the same IP addresses.
The advisory also warns that North Korean IT workers may reuse identities stolen during WaterPlum attacks to impersonate victims and obtain jobs.
Investigators discovered that members of the WaterPlum operation used AI face-swapping software during online interviews. The individuals then turned off their cameras and blamed network problems.

The FBI and Japanese police assess that WaterPlum officials and some North Korean IT personnel operate under the country’s 313 Directorate. The directorate is part of North Korea’s Arms Industry Administration, which is responsible for weapons research and production.
Japan’s National Police Agency announced that, for the first time in the country, authorities had identified, investigated, and dismantled a “laptop farm” used by North Korean IT workers. Investigators also found evidence that hundreds of millions of yen had been sent overseas.
How companies and developers can defend against WaterPlum
The advisory warns companies to carefully verify the identity, location, and qualifications of job applicants. Organizations should also limit each worker’s access to only the systems and data necessary to perform the job.
Developers should avoid running unknown code outside a sandbox. They should also inspect provided files and source code for commands that download or execute additional payloads.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



