North Korean WaterPlum Hackers Compromise 30,000 Devices and Steal $10.7 Million in Crypto
A joint advisory from Japanese, U.S., Australian, and German law enforcement agencies warns that the North Korean hacking group WaterPlum compromises at least 30,000 devices across more than 100 countries between December 2025 and July 2026. The attackers transfer more than $10.7 million in stolen cryptocurrency to North Korea and drain funds or credentials from over 7,000 cryptocurrency wallets. WaterPlum forms part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to fund the regime's weapons programs.
WaterPlum operates through a multi-year campaign known as "Contagious Interview," which targets job seekers by impersonating legitimate AI, cryptocurrency, and NFT companies. The attackers use recruiting and freelance platforms to approach victims, then lure them during fake interviews and coding tests into downloading malicious projects, troubleshooting phony video-conferencing problems, or executing malicious code. The advisory links several malware families to the operation, including BeaverTail, a JavaScript malware hidden in npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie and OtterCandy, remote-access trojans and information stealers; and StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects.
Once a device falls victim, the attackers steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots. The threat actors then use their access to pivot into victims' employers' or clients' networks, expanding the attacks to intellectual property theft and espionage. Security experts urge job seekers and freelance platforms to remain cautious of unsolicited interview requests, avoid downloading untrusted projects, and never execute code from unknown repositories.