North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
FBI and Japanese police advisory ties North Korea's WaterPlum campaign to $10.5M stolen from job seekers via fake-recruiter malware on 30,000 devices.
A joint advisory from the FBI, US Defense Department, Japan's National Police Agency and partners describes 'WaterPlum', North Korean cyber actors posing as AI and blockchain companies to recruit job seekers. Between December 2025 and July 2026 the group infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets, totaling over $10.5 million. Victims, mostly web designers, engineers and crypto specialists in Japan and elsewhere, were contacted via social media and freelance portals and told to download files during interviews, leading to infection with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware plus remote management tools. The campaign is intertwined with DPRK IT-worker laptop-farm schemes and is attributed to North Korea's General Bureau of the Munitions Industry Department; Japanese police disrupted a laptop farm for the first time.
- $10.5M stolen from roughly 7,000 crypto wallets in 100 countries
- 30,000+ devices infected via fake recruiter interviews on freelance platforms
- BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle strains deployed
- Infostealers and remote management tools maintained long-term access
- Tied to DPRK IT-worker scheme; Japanese police disrupted a laptop farm
Full article767 words · extracted from therecord.media · click to collapse
More than $10.5 million has been stolen by North Korean hackers targeting job seekers as part of a long-running cyber campaign to infiltrate tech companies and fill Pyongyang’s coffers with illicitly gained funds. The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. The report said that between December 2025 and July 2026, WaterPlum hackers infected at least 30,000 devices across 100 countries and stole funds or credentials from about 7,000 cryptocurrency wallets. The primary targets of the campaign are web designers, engineers and cryptocurrency specialists. Friday’s advisory said the WaterPlum scheme is specifically victimizing IT professionals in Japan and other countries. Job seekers are contacted through social media platforms, gig work websites and freelance portals. Applicants are instructed to download files during the interview process, allowing the hackers to infect devices and steal cryptocurrency wallet credentials alongside other information. Japanese police found variants of the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware strains on victim devices. WaterPlum actors typically installed infostealers and remote management tools to maintain their access to victim devices. Other North Korean hackers were seen using identity documents stolen from victims to obtain employment elsewhere. In April, incident responders uncovered a similar campaign involving the same strains of malware where hackers stole up to $12 million in cryptocurrency through malware attacks on personal devices. Those incidents were also targeted at blockchain developers who were contacted by fake recruiters through LinkedIn. In addition to stealing a person’s cryptocurrency, the hackers maintained their access to victim devices in the hopes that the person got hired at other tech firms, allowing North Korean hackers to piggyback into corporate systems. At least one blockchain company previously confirmed that a version of this tactic was responsible for a damaging cryptocurrency theft incident. The law enforcement agencies tied WaterPlum to other North Korean efforts to infect the devices of job applicants. Dating back to 2020, cybersecurity firms have identified similar North Korean campaigns targeting job seekers in the defense industry, and Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted with malicious emails from fake recruiters claiming to be from Disney, Google and Oracle. According to the report, the WaterPlum campaign is deeply intertwined with the IT worker scheme — where North Koreans steal or purchase identities to get hired in lucrative roles at technology firms in the U.S. or Europe. Japanese officials noted that for the first time, they disrupted a laptop farm operated by a Japanese national and found evidence that several hundred million Japanese yen was sent to addresses outside of the country. The FBI has uncovered dozens of laptop farms across the U.S. that are used by North Koreans to make it look like they are working locally. The report notes that WaterPlum actors and North Korean IT workers used the same IP addresses when accessing laptop farms or applying for positions at Japanese cryptocurrency companies. The laptop farm disruption allowed Japanese officials to get an inside look at a variety of North Korean schemes. North Korean IT workers who interviewed for roles were seen using AI face-swapping software, text-to-speech software that gave them Japanese pronunciations and other AI translation tools. The report said the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department — which is within the Central Committee of the Workers Party of Korea. Experts previously told Recorded Future News that multiple government departments within North Korea essentially run squads of their own cyber workers who participate in a variety of revenue-generating schemes, including legitimate IT work, cryptocurrency thefts and data extortion. “While North Korean IT workers primarily focus on revenue generation, there have been cases of additional malicious cyber activity. In one case, a North Korean IT worker extorted a company over payment and published its proprietary source code online,” the advisory said. “In another case, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.” Ties to IT worker schemes
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme