North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group’s activity.
WaterPlum is linked to a multi-year campaign known as “Contagious Interview,” which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.
The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.
During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.
“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,” reads the advisory.
“WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).”
The advisory links several malware families to WaterPlum operations, including:
- BeaverTail: JavaScript malware concealed in npm packages.
- InvisibleFerret: Python-based backdoor.
- OtterCookie: JavaScript remote-access trojan and information stealer.
- OtterCandy: Malware combining OtterCookie and RAT capabilities.
- StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots.
They may also use access to infected computers to pivot to their employers’ or clients’ networks, expanding the attacks to intellectual property theft and espionage.
The agencies also directly connect WaterPlum to North Korea’s fraudulent IT worker operations, stating that some WaterPlum hackers also work as remote IT workers performing web development for clients and that the two groups have used the same IP addresses.
The advisory also warns that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.
Investigators also found that the WaterPlum actors use AI face-swapping software during online interviews, then turn off their cameras and blame network problems.

The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country’s 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea’s weapons research and production.
Japan’s National Police Agency says authorities identified, investigated, and dismantled a North Korean IT-worker “laptop farm” in the country for the first time, finding evidence that several hundred million yen had been transferred abroad.
The advisory warns companies to carefully verify job applicants’ identities, locations, and qualifications and restrict their access to only the systems and data required to perform their jobs.
Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.


