BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 18, 2026 · 4 min read · Original story

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds.

The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.

The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets. The primary targets of the campaign are web designers, engineers and cryptocurrency specialists.

Friday’s advisory said the WaterPlum scheme is specifically victimizing IT professionals in Japan and other countries. Job seekers are contacted through social media platforms, gig work websites and freelance portals. Applicants are instructed to download files during the interview process, allowing the hackers to infect devices and steal cryptocurrency wallet credentials alongside other information.

Japanese police found variants of the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware strains on victim devices. WaterPlum actors typically installed infostealers and remote management tools to maintain their access to victim devices. Other North Korean hackers were seen using identity documents stolen from victims to obtain employment elsewhere.

In April, incident responders uncovered a similar campaign involving the same strains of malware where hackers stole up to $12 million in cryptocurrency through malware attacks on personal devices. Those incidents were also targeted at blockchain developers who were contacted by fake recruiters through LinkedIn.

In addition to stealing a person’s cryptocurrency, the hackers maintained their access to victim devices in the hopes that the person got hired at other tech firms, allowing North Korean hackers to piggyback into corporate systems. At least one blockchain company previously confirmed that a version of this tactic was responsible for a damaging cryptocurrency theft incident.

The law enforcement agencies tied WaterPlum to other North Korean efforts to infect the devices of job applicants.

Dating back to 2020, cybersecurity firms have identified similar North Korean campaigns targeting job seekers in the defense industry, and Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted with malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.

Ties to IT worker schemes

According to the report, the WaterPlum campaign is deeply intertwined with the IT worker scheme — where North Koreans steal or purchase identities to get hired in lucrative roles at technology firms in the U.S. or Europe.

Japanese officials noted that for the first time, they disrupted a laptop farm operated by a Japanese national and found evidence that several hundred million Japanese yen was sent to addresses outside of the country. The FBI has uncovered dozens of laptop farms across the U.S. that are used by North Koreans to make it look like they are working locally.

The report notes that WaterPlum actors and North Korean IT workers used the same IP addresses when accessing laptop farms or applying for positions at Japanese cryptocurrency companies.

The laptop farm disruption allowed Japanese officials to get an inside look at a variety of North Korean schemes. North Korean IT workers who interviewed for roles were seen using AI face-swapping software, text-to-speech software that gave them Japanese pronunciations and other AI translation tools.

The report said the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department — which is within the Central Committee of the Workers Party of Korea.

Experts previously told Recorded Future News that multiple government departments within North Korea essentially run squads of their own cyber workers who participate in a variety of revenue-generating schemes, including legitimate IT work, cryptocurrency thefts and data extortion.

“While North Korean IT workers primarily focus on revenue generation, there have been cases of additional malicious cyber activity. In one case, a North Korean IT worker extorted a company over payment and published its proprietary source code online,” the advisory said.

“In another case, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.”

References in this story

  1. North Korean hackers siphon more than $12 million from crypto users in sprawling campaign therecord.media Researchers said the group stole up to $12 million in cryptocurrency in the first three months of 2026 through malware attacks on personal devices.
  2. North Korean hackers behind $50 million crypto heist of Radiant Capital therecord.media Researchers attributed the attack on the cryptocurrency platform to a group housed within North Korea’s Reconnaissance General Bureau (RGB).
  3. Malicious North Korean packages appear again in open source code repository therecord.media Researchers say that North Korean groups intent on stealing cryptocurrency and information are continuing to drop malicious code into the npm repository, which is popular with JavaScript developers.
  4. North Korean hacking group targeting European drone maker with ScoringMathTea malware therecord.media Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recruiters at top…
  5. North Korean hackers target employees of news outlets, software vendors and more through Chrome vulnerability therecord.media Google has released a report identifying two North Korean government hacking campaigns that exploited a Google Chrome 0-day.
  6. New Jersey men given lengthy sentences for running North Korean laptop farms therecord.media The DOJ said Kejia Wang, 42, was sentenced to nine years in prison and Zhenxing Wang, 39, was given a nearly eight-year sentence for an operation that generated more than $5 million for the government of North Korea.
  7. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  8. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  9. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  10. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news