Newsroom

North Korean Group WaterPlum Infects 30,000 Devices, Steals $10.7 Million in Crypto

18 September, 2026   /   News   /  AI   /   Tags:  waterplum, north, korean, remote, laptop

North Korean Group WaterPlum Infects 30,000 Devices, Steals $10.7 Million in Crypto

Japan, the FBI and partners attribute a global campaign that targeted IT professionals with fake job offers and malware to a unit linked to Pyongyang’s munitions industry

Seven security agencies from Japan, the United States, Australia and Germany issued a joint public attribution on September 18, 2026, naming the North Korean cyber group WaterPlum, also known as Contagious Interview, as responsible for a widespread campaign that compromised more than 30,000 computers and drained cryptocurrency from thousands of accounts.

According to the advisory, the group transferred the equivalent of 1.7 billion Japanese yen, or about $10.71 million, in stolen digital assets to North Korea between December 2025 and July 2026. The operation affected devices in over 100 countries and compromised credentials for roughly 7,000 cryptocurrency accounts.

Attribution and Command Structure

The agencies involved include Japan’s National Police Agency and National Cybersecurity Office, the U.S. Federal Bureau of Investigation, the Department of Defense Cyber Crime Center, Australia’s ASD Cyber Security Centre, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution.

Officials assess that WaterPlum operates under the 313 General Bureau of the Munitions Industry Department, which falls under the Central Committee of the Workers’ Party of Korea. The group’s activities form part of broader efforts by North Korean actors to generate revenue that supports the country’s weapons programs. North Korean authorities have previously denied similar allegations of state-directed cryptocurrency theft.

How the Fake Recruitment Scheme Operated

WaterPlum operators posed as hiring managers or recruiters for artificial intelligence firms, cryptocurrency ventures and non-fungible token startups. They contacted software developers, web designers and specialists in blockchain and Web3 technologies through social media and online job platforms, presenting attractive remote employment opportunities.

Victims were directed to complete technical interviews or coding assignments. In many cases they were instructed to download and execute files presented as part of the assessment process. These files contained malicious Node Package Manager packages carrying malware strains identified as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.

Once installed, the malware established persistent backdoor access through remote-access tools. It harvested browser passwords, keystrokes, screenshots, private keys and seed phrases used to control cryptocurrency wallets. Some operators also employed artificial-intelligence face-swapping software during video interviews to impersonate legitimate recruiters.

From around December 2025 through July 2026, WaterPlum exploited at least 30,000 PCs in over 100 countries. The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.
Joint advisory from the FBI and partner agencies

Dual Role as Remote IT Workers and Laptop Farms

Beyond the malware campaign, some WaterPlum actors functioned as North Korean information-technology workers. These individuals, operating from locations including North Korea, China and Russia, secured remote programming and web-development contracts under false identities and routed their earnings back to the regime.

To mask the origin of the work, the network relied on local facilitators who ran laptop farms and virtual private servers. Japanese authorities identified, investigated and dismantled one such laptop farm operated by an enabler inside Japan, marking the first successful action of its kind in the country. Evidence showed that several hundred million yen in cryptocurrency had been moved from Japan to foreign destinations.

Investigators noted substantial operational overlap between WaterPlum and the wider network of North Korean remote IT workers, including shared internet protocol addresses used for laptop farms, cloud services and applications to Japanese cryptocurrency exchanges.

Scale and Broader Context

The stolen funds and compromised data have supported further North Korean cyber operations. The advisory forms part of ongoing international efforts to disrupt revenue streams that finance Pyongyang’s military and weapons development. North Korean-linked actors have been associated with the theft of billions of dollars in cryptocurrency over the past decade, a pattern that G7 leaders previously identified as a significant security concern.

Authorities continue to pursue facilitators who provide infrastructure or employment cover for these schemes. The FBI has prosecuted U.S.-based individuals who assisted North Korean IT workers, while Japanese police obtained evidence of substantial outbound cryptocurrency transfers linked to the laptop-farm activity.

Guidance for Potential Targets

Security agencies advised software developers and IT professionals to treat unsolicited job offers with caution. They recommended against executing code received from unknown third parties on machines that handle cryptocurrency assets or sensitive personal data. Any unknown code should be run only inside a sandbox or virtual machine after verification that it contains no obfuscated sections.

If antivirus software detects infection or compromise is suspected, the affected device should be immediately disconnected from the internet to prevent further external communication. Companies hiring remote developers were urged to strengthen candidate-vetting procedures to reduce the risk of engaging North Korean IT workers operating under false identities.

The joint public attribution aims to increase pressure on the network by exposing its methods, infrastructure and command links, while encouraging additional international cooperation against the dual threats of malware-driven theft and illicit remote labor schemes.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.