North Korean WaterPlum Hackers Steal $10.7 Million in Crypto, Compromise 30,000 Devices
A new joint advisory from global law enforcement agencies reveals that the North Korean hacking group **WaterPlum** has compromised at least 30,000 devices worldwide and siphoned over $10.7 million in cryptocurrency. The group, linked to the 'Contagious Interview' campaign, targets job seekers and leverages sophisticated social engineering tactics and malicious software to fund the DPRK's weapons programs.
A multi-national law enforcement advisory has exposed the extensive cyber operations of **WaterPlum**, a North Korean state-sponsored hacking group. According to the joint report from Japanese, US, Australian, and German authorities, **WaterPlum** compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, transferring more than $10.7 million in stolen cryptocurrency to North Korea.
This activity is part of a broader, multi-year campaign known as "Contagious Interview," which has previously targeted job seekers with malicious **npm** packages to deploy malware.
### Sophisticated Recruitment Scams
The attackers impersonate legitimate AI, cryptocurrency, and NFT companies, or leverage recruiting and freelance platforms to engage with job seekers. During fake interviews and coding tests, victims are instructed to download malicious projects, troubleshoot fabricated video-conferencing issues, or execute harmful code.

*Source: FBI*
**WaterPlum** operates within a larger ecosystem of North Korean threat actors, all engaged in financially motivated attacks designed to generate revenue for the regime and fund its illicit weapons programs.
"**WaterPlum** actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," states the advisory. "**WaterPlum** actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."
### Malware Families and Tactics
The advisory links several malware families to **WaterPlum** operations:
* **BeaverTail:** JavaScript malware disguised within **npm** packages.
* **InvisibleFerret:** A Python-based backdoor.
* **OtterCookie:** A JavaScript remote-access trojan (RAT) and information stealer.
* **OtterCandy:** Malware combining **OtterCookie** and RAT capabilities.
* **StoatWaffle:** Modular **Node.js** malware delivered via malicious **Visual Studio Code** projects, utilizing configuration files to execute code upon opening and trusting a folder.
Once a target is compromised, the attackers aim to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and sensitive documents. They also capture screenshots and may pivot from infected personal devices to gain access to employers' or clients' networks, facilitating intellectual property theft and espionage.
### Connection to Fraudulent IT Worker Operations
The agencies also directly link **WaterPlum** to North Korea's fraudulent IT worker operations. Some **WaterPlum** hackers are reportedly also employed as remote IT workers performing web development for clients, with both groups using the same IP addresses. The advisory further warns that North Korean IT workers reuse identity documents stolen in **WaterPlum** attacks to impersonate victims and secure legitimate jobs.
Investigators also observed **WaterPlum** actors using AI face-swapping software during online interviews, then disabling their cameras and citing network problems as an excuse.

*Source: FBI*
Both the **FBI** and Japanese police assess that **WaterPlum** actors and certain North Korean IT workers operate under the country's **313 General Bureau**, which is part of the Munitions Industry Department responsible for North Korea's weapons research and production.
Japan's National Police Agency reported the first-ever identification, investigation, and dismantlement of a North Korean IT-worker "laptop farm" within the country, uncovering evidence of several hundred million yen transferred abroad.
### Recommendations for Defense
The advisory urges companies to meticulously verify job applicants' identities, locations, and qualifications. It also recommends restricting access for new hires to only the systems and data essential for their roles. Developers are advised to avoid running unknown code outside a sandbox environment and to thoroughly inspect provided files and code for commands that might fetch additional payloads.