Zero Day Room
Live
Regulation & compliance

WaterPlum Hackers Stole $10.7 Million in Global Campaign

A North Korean hacking group compromised 30,000 devices worldwide over eight months, stealing over $10.7 million in cryptocurrency, according to a joint

A North Korean hacking group compromised 30,000 devices worldwide over eight months, stealing over $10.7 million in...

A joint advisory from Japanese, US, Australian, and German authorities warns that the North Korean hacking group WaterPlum infected at least 30,000 devices globally between December 2025 and July 2026. The group transferred more than $10.7 million in stolen cryptocurrency to North Korea during this period.

WaterPlum is part of the long-running "Contagious Interview" campaign. It targets job seekers by impersonating legitimate AI, cryptocurrency, and NFT companies on recruiting platforms. During fake interviews and coding tests, victims are tricked into downloading malicious projects, troubleshooting fake video-conferencing issues, or executing harmful code.

The advisory states that WaterPlum actors have exfiltrated funds or credentials from over 7,000 cryptocurrency wallets. The group is part of a broader ecosystem of North Korean threat actors conducting financially motivated attacks to generate revenue for the regime and fund its weapons programs.

Malware Families Used in Attacks

The advisory links several distinct malware families to WaterPlum operations.

Once a device is compromised, the attackers steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents. They also capture screenshots. The group may use access to infected personal computers to pivot to victims' employers' or clients' networks, expanding operations to intellectual property theft and espionage.

Links to Fraudulent IT Worker Operations

Law enforcement directly connects WaterPlum to North Korea's fraudulent IT worker schemes. The advisory states that some WaterPlum hackers also work as remote IT workers performing web development for clients. The two groups have used the same IP addresses.

Investigators warn that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs. The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country's 313 General Bureau. This bureau is part of the Munitions Industry Department responsible for weapons research and production.

Evasion Tactics and Enforcement Action

The attackers use sophisticated evasion techniques during their fake interviews. Investigators found that WaterPlum actors use AI face-swapping software during online meetings, then turn off their cameras and blame network problems.

Japan's National Police Agency reported a significant enforcement action. Authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" in Japan for the first time. They found evidence that several hundred million yen had been transferred abroad from this operation.

The joint advisory provides guidance for companies and developers. It warns organizations to carefully verify job applicants' identities, locations, and qualifications. Companies should restrict remote workers' access to only the systems and data required for their jobs. Developers are advised to avoid running unknown code outside a sandbox and to inspect provided files and code for commands that fetch additional payloads.

Related coverage

More from Regulation & compliance