North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group's activity.
WaterPlum is linked to a multi-year campaign known as "Contagious Interview," which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.
The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.
During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.
Source: FBIWaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," reads the advisory.
"WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."
The advisory links several malware families to WaterPlum operations, including:
- BeaverTail: JavaScript malware concealed in npm packages.
- InvisibleFerret: Python-based backdoor.
- OtterCookie: JavaScript remote-access trojan and information stealer.
- OtterCandy: Malware combining OtterCookie and RAT capabilities.
- StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots.
They may also use access to infected computers to pivot to their employers' or clients' networks, expanding the attacks to intellectual property theft and espionage.
The agencies also directly connect WaterPlum to North Korea's fraudulent IT worker operations, stating that some WaterPlum hackers also work as remote IT workers performing web development for clients and that the two groups have used the same IP addresses.
The advisory also warns that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.
Investigators also found that the WaterPlum actors use AI face-swapping software during online interviews, then turn off their cameras and blame network problems.
Source: FBIThe FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country's 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea's weapons research and production.
Japan's National Police Agency says authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" in the country for the first time, finding evidence that several hundred million yen had been transferred abroad.
The advisory warns companies to carefully verify job applicants' identities, locations, and qualifications and restrict their access to only the systems and data required to perform their jobs.
Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.
References in this story
- 北朝鮮サイバー攻撃グループ「WaterPlum」(ウォータープラム)及び北朝鮮IT労働者に関する我が国、米国、豪州及びドイツによるパブリック・アトリビューションについて|警察庁Webサイト www.npa.go.jp
- Internationaler Sicherheitshinweis: Illegale Devisenbeschaffung durch nordkoreanische Cyberaktivitäten www.verfassungsschutz.de Die japanische National Police Agency (NPA) hat in Zusammenarbeit mit dem Bundesamt für Verfassungsschutz (BfV), dem Bundesnachrichtendienst (BND), dem Federal Bureau of Investigation (FBI) sowie weiteren…
- New wave of ‘fake interviews’ use 35 npm packages to spread malware www.bleepingcomputer.com A new wave of North Korea's 'Contagious Interview' campaign is targeting job seekers with malicious npm packages that infect dev's devices with infostealers and backdoors.
- North Korean XORIndex malware hidden in 67 malicious npm packages www.bleepingcomputer.com North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems.
- North Korean hackers now launder stolen crypto via YoMix tumbler www.bleepingcomputer.com The North Korean hacker collective Lazarus, infamous for having carried out numerous large-scale cryptocurrency heists over the years, has switched to using YoMix bitcoin mixer to launder stolen proceeds.
- US woman allegedly aided North Korean IT workers infiltrate 300 firms www.bleepingcomputer.com The U.S. Justice Department charged five individuals today, a U.S. Citizen woman, a Ukrainian man, and three foreign nationals, for their involvement in cyber schemes that generated revenue for North Korea's nuclear…



