A North Korean hacking group infected at least 30,000 devices across more than 100 countries, according to a joint security advisory. Authorities say the WaterPlum hackers also stole cryptocurrency and account credentials from over 7,000 wallets.

WaterPlum Hackers Target 30,000 Devices

Authorities tracked WaterPlum’s activity between December 2025 and July 2026.

During that period, the group allegedly compromised at least 30,000 devices worldwide. It also extracted funds or credentials from more than 7,000 cryptocurrency wallets.

The attackers transferred cryptocurrency worth approximately ¥1.7 billion to North Korea. That amount equals around $10.7 million.

Law enforcement and security agencies from Japan, the US, Australia and Germany jointly investigated the campaign. Together, they traced its international reach and documented its attack methods.

Fake Interviews Deliver Malware

WaterPlum has links to a long-running campaign known as Contagious Interview.

The attackers impersonate legitimate companies operating in the AI, cryptocurrency and NFT sectors. They also contact developers through recruitment websites and freelance platforms.

After approaching a target, the hackers arrange a fake job interview or coding assessment. They then persuade the victim to download a software project or solve a technical problem.

In some cases, the attackers claim that the candidate has a video-conferencing issue. They instruct the person to download a supposed fix or run malicious commands.

Other attacks use compromised coding projects and harmful npm packages. Once the victim executes the files, the malware infects the device.

Authorities Identify Five Malware Families

The advisory connects WaterPlum to several malware families.

BeaverTail uses malicious JavaScript hidden inside npm packages. Meanwhile, InvisibleFerret provides the attackers with a Python-based backdoor.

OtterCookie combines remote-access functions with information-stealing capabilities. Another variant, OtterCandy, expands those features with additional remote-access tools.

The fifth family, StoatWaffle, uses modular Node.js malware. Attackers often hide it inside malicious Visual Studio Code projects.

These projects can contain configuration files that automatically execute code after a developer opens and trusts the folder. Therefore, an apparently routine coding test can compromise a device.

Malware Steals Credentials and Cryptocurrency

After gaining access, the WaterPlum hackers collect valuable information from the infected system.

Their malware can steal browser credentials, cryptocurrency private keys and wallet seed phrases. It may also capture clipboard contents, keystrokes, documents and screenshots.

The attackers can then use the stolen information to access online accounts and cryptocurrency wallets. Moreover, credentials from one device may provide entry into additional services.

WaterPlum does not always stop at the victim’s computer. Instead, the group may use the infected device to reach an employer’s or client’s network.

This access can support further financial theft. It may also allow the attackers to steal intellectual property or conduct espionage.

Campaign Supports North Korean Revenue Operations

Authorities consider WaterPlum part of a broader network of North Korean cyber operations.

These groups conduct financially motivated attacks to generate revenue for the country. According to the advisory, the stolen funds may help finance North Korea’s weapons programmes.

Investigators also found connections between WaterPlum and North Korea’s fraudulent remote IT worker schemes.

Some WaterPlum members reportedly perform web development work for foreign clients while posing as legitimate remote workers. Furthermore, investigators discovered that the hackers and fraudulent workers had used some of the same IP addresses.

The two operations may also share stolen information. Authorities warn that North Korean IT workers reuse identity documents collected during WaterPlum attacks.

They can then impersonate the victims and apply for remote jobs under false identities.

Hackers Use AI During Job Interviews

Investigators say some North Korean operatives use AI face-swapping software during video interviews.

The technology allows them to appear as someone else while speaking with potential employers. However, they may disable their cameras after the initial introduction and blame connection problems.

This method can make identity verification more difficult. It may also help applicants conceal their true location and appearance.

The FBI and Japanese police link WaterPlum members and some fraudulent IT workers to North Korea’s 313 General Bureau.

The bureau forms part of the Munitions Industry Department, which oversees the country’s weapons research and production.

Japan Dismantles a Laptop Farm

Japan’s National Police Agency also announced action against a North Korean remote-worker operation.

Authorities identified, investigated and dismantled a North Korean IT worker “laptop farm” in Japan. The operation marked the first known case of its kind in the country.

Laptop farms allow overseas workers to appear as though they operate from another location. Locally hosted computers can conceal the workers’ real geographical positions from employers.

Investigators found evidence that the operation had transferred several hundred million yen overseas.

Companies Urged to Verify Applicants

The joint advisory urges companies to strengthen their recruitment and security procedures.

Employers should carefully confirm each applicant’s identity, location and professional qualifications. They should also watch for inconsistencies during video interviews.

Moreover, companies should limit new workers’ access to essential systems and data. This approach can reduce the damage if an attacker secures a position using a stolen identity.

Developers should never run unknown code directly on their primary devices. Instead, they should inspect unfamiliar projects inside an isolated sandbox.

They should also examine configuration files for commands that download additional payloads. Finally, organisations should treat unusual requests to install software during interviews as a potential warning sign.


0 responses to “WaterPlum Hackers Infected 30,000 Devices Worldwide”