ZeroHour
Threat actor

WaterPlum

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

North Korea's fake job interviews infected 30,000 devices

International advisories attribute 30,000 compromised devices, 7,000 crypto wallets, and $10.71 million in thefts to North Korea's WaterPlum fake-recruiter malware campaigns.

Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued a joint advisory update Thursday on WaterPlum, North Korea's fake-recruiter campaign. Operators pose as recruiters targeting web designers, engineers, and cryptocurrency/Web3 specialists with bogus coding tests that install remote access trojans and information stealers. The attackers compromised more than 7,000 crypto wallets and stole at least $10.71 million, funneled to Pyongyang. The scheme complements North Korea's IT worker fraud, estimated at roughly $500 million annually from about 100,000 workers worldwide.

The Register · Security · 3h agoThreat actor in the wild

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

US, Japanese, German, and Australian agencies warn North Korea's WaterPlum gang poses as recruiters, infecting 30,000+ devices and stealing about $11 million in crypto.

The FBI, DoD Cyber Crime Center, and agencies from Japan, Germany, and Australia attributed WaterPlum (Contagious Interview) to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea. The group poses as recruiters from fake AI, cryptocurrency, and NFT companies to target software developers and IT professionals, infecting more than 30,000 devices in over 100 countries. Operators have transferred roughly $11 million in cryptocurrency from more than 7,000 wallets to North Korea. Japanese authorities dismantled a laptop farm for the first time, and WaterPlum actors substantially overlap with North Korean IT worker schemes, sharing IP addresses and infrastructure.

CyberScoop · 4h agoThreat actor in the wild 3 sources

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

FBI and Japanese police advisory ties North Korea's WaterPlum campaign to $10.5M stolen from job seekers via fake-recruiter malware on 30,000 devices.

A joint advisory from the FBI, US Defense Department, Japan's National Police Agency and partners describes 'WaterPlum', North Korean cyber actors posing as AI and blockchain companies to recruit job seekers. Between December 2025 and July 2026 the group infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets, totaling over $10.5 million. Victims, mostly web designers, engineers and crypto specialists in Japan and elsewhere, were contacted via social media and freelance portals and told to download files during interviews, leading to infection with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware plus remote management tools. The campaign is intertwined with DPRK IT-worker laptop-farm schemes and is attributed to North Korea's General Bureau of the Munitions Industry Department; Japanese police disrupted a laptop farm for the first time.

The Recordupdated · 4h agofirst · 16h agoThreat actor in the wild 3 sources