LmCast :: Stay tuned in

North Korean WaterPlum hackers infected 30,000 devices worldwide

Recorded: Sept. 19, 2026, 2 p.m.

Original Summarized

North Korean WaterPlum hackers infected 30,000 devices worldwide

News

Featured
Latest

OpenAI details more cases of AI agents taking unauthorized actions

Brevo supply-chain attack injected ClickFix scripts on customer sites

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

North Korean WaterPlum hackers infected 30,000 devices worldwide

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

Get 25 hours of ChatGPT & AI training for just $19.99

Calling viral AI actress Tilly Norwood? Agree to a face scan first

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityNorth Korean WaterPlum hackers infected 30,000 devices worldwide

North Korean WaterPlum hackers infected 30,000 devices worldwide

By Bill Toulas

September 19, 2026
10:05 AM
0

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group's activity.
WaterPlum is linked to a multi-year campaign known as "Contagious Interview," which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.
The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.
During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

Source: FBI
WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," reads the advisory.
"WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."
The advisory links several malware families to WaterPlum operations, including:
BeaverTail: JavaScript malware concealed in npm packages.
InvisibleFerret: Python-based backdoor.
OtterCookie: JavaScript remote-access trojan and information stealer.
OtterCandy: Malware combining OtterCookie and RAT capabilities.
StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots.
They may also use access to infected computers to pivot to their employers' or clients' networks, expanding the attacks to intellectual property theft and espionage.
The agencies also directly connect WaterPlum to North Korea's fraudulent IT worker operations, stating that some WaterPlum hackers also work as remote IT workers performing web development for clients and that the two groups have used the same IP addresses.
The advisory also warns that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.
Investigators also found that the WaterPlum actors use AI face-swapping software during online interviews, then turn off their cameras and blame network problems.

Source: FBI
The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country's 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea's weapons research and production.
Japan's National Police Agency says authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" in the country for the first time, finding evidence that several hundred million yen had been transferred abroad.
The advisory warns companies to carefully verify job applicants' identities, locations, and qualifications and restrict their access to only the systems and data required to perform their jobs.
Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Hackers steal $23.7 million in crypto from Ostium in off-chain attackCalifornia man admits to laundering crypto stolen in $230M heistCronos blockchain restarts after $74 million Tectonic exploitHackers breach govt webmail while running parallel crypto fraudApple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Crypto theft
CryptoCurrency
Financial Theft
IT Worker Scheme
Job
North Korea
WaterPlum

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment
Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Windows 11 KB5124008 update breaks domain trust for some users

Cisco warns of max severity ISE zero-day exploited in attacks

Microsoft shares workaround for Windows domain login issues

Sponsor Posts

Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Overdue a password health-check? Audit your Active Directory for free

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A joint law enforcement advisory from Japanese, US, Australian, and German authorities warns that the North Korean hacking group WaterPlum compromised a minimum of 30,000 devices across more than 100 countries between December 2025 and July 2026, exfiltrating over $10.7 million in cryptocurrency to North Korea. This activity is linked to a multi-year campaign termed "Contagious Interview," which targets job seekers by impersonating legitimate entities such as AI, cryptocurrency, or NFT companies, or by utilizing recruiting and freelance platforms. The attackers manipulate victims during fake interviews and coding tests, instructing them to download projects, resolve supposed video-conferencing issues, or execute malicious code to gain access.

The WaterPlum actors operate within a broader ecosystem of North Korean threat actors engaged in financially motivated attacks aimed at funding the regime's weapons programs. The advisory specifies several malware families associated with these operations, including BeaverTail, a JavaScript malware concealed within npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie, a JavaScript remote-access trojan and information stealer; OtterCandy, which is a composite malware combining OtterCookie and Remote Access Trojan capabilities; and StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects that executes code upon folder opening. Once a device is compromised, the attackers execute tactics to steal sensitive data, including browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, in addition to capturing screenshots. Furthermore, they leverage these infected computers to pivot into the networks of employers or clients, enabling attacks focused on intellectual property theft and espionage.

The advisory further indicates a direct connection between WaterPlum actors and North Korean IT worker operations, noting that some hackers function as remote IT workers performing web development for clients, often utilizing the same IP addresses. Investigators also found evidence that North Korean IT workers reuse stolen identity documents obtained through WaterPlum attacks to impersonate victims and secure employment. The advisory further connects WaterPlum to North Korea's weapons research and production infrastructure, noting that the actors and some IT workers operate under the Munitions Industry Department, specifically the 313 General Bureau. Japan's National Police Agency recently dismantled a North Korean IT-worker laptop farm, confirming transfers of hundreds of millions of yen abroad through this channel. Consequently, the advisory strongly warns that organizations must rigorously verify the identities, locations, and qualifications of job applicants, restrict their access to only the systems and data strictly necessary for their roles, and encourage developers to avoid executing unknown code outside secure sandboxes while closely inspecting provided files and code for additional payloads.