Allies Say North Korea's WaterPlum Hit 30,000 Devices
A joint advisory says North Korea-linked WaterPlum infected at least 30,000 devices in fake job interviews and stole about $10.71 million from over 7,000 crypto wallets.
A joint advisory from Japan's National Police Agency, the FBI, the U.S. Defense Cyber Crime Center, Australia's ACSC, and German agencies attributes WaterPlum—also tracked as Contagious Interview—to North Korea, including the 313 General Bureau linked to the regime's IT-worker scheme. Between December 2025 and July 2026, operators posed as recruiters or employers for AI, cryptocurrency, and NFT roles and infected at least 30,000 devices in more than 100 countries, though headlines vary between "at least," "over," and "about" 30,000. They took funds or credentials from more than 7,000 cryptocurrency wallets, with the loss cited as at least 1.7 billion yen and reported as either $10.7 million or the more specific $10.71 million sent toward North Korea. Most reports name BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, delivered through fake coding tests, NPM packages, and Visual Studio Code projects; The Hacker News lists FlexibleFerret instead of OtterCandy and StoatWaffle. One outlet says the recruiter tactic dates to at least 2022, while the infection and theft totals above are tied to December 2025–July 2026. Japan dismantled a related laptop farm—described by SecurityWeek as its first confirmed North Korean site—and reports also describe AI face-swapping, Discord recruitment of interview proxies, and the risk that an infected developer becomes an entry point into an employer network.
- A joint advisory from Japan's NPA, the FBI, the U.S. Defense Cyber Crime Center, Australia's ACSC, and German agencies—dated September 18 by one outlet—attributes WaterPlum, also known as Contagious Interview, to North Korea's 313 General…
- At least 30,000 devices in more than 100 countries were infected between December 2025 and July 2026; headlines also say "over" or "about" 30,000.
- Funds or credentials were taken from more than 7,000 cryptocurrency wallets; losses are given as at least JPY 1.7 billion, reported as $10.7 million or $10.71 million, and moved toward North Korea.
- Malware named in most reports includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle; The Hacker News instead lists FlexibleFerret and omits OtterCandy and StoatWaffle.
- Operators posed as AI, crypto, or NFT recruiters on LinkedIn, job boards, and freelance sites, using coding tests, malicious NPM packages, and Visual Studio Code projects; some reports also describe AI face-swapping.
- Japan dismantled a laptop farm tied to North Korean IT workers—called the country's first confirmed such site by SecurityWeek—and one report says interview proxies were recruited on Discord.
- One report says the fake-recruiter tactic dates to at least 2022, while the 30,000-device and loss figures are tied by others to December 2025–July 2026.
- Sources say a compromised developer can open a path into an employer's network; SecurityWeek also mentions extortion material.
Coverage timelineoldest first · each row is one article
- · 6d agoNorth Korean WaterPlum Hackers Infect 30,000 PCs via Fake Job Interviews, Steal $10.7M Crypto
Cyber Security News· 78
North Korean WaterPlum actors posed as recruiters to infect 30,000 developers' PCs and steal $10.7M in cryptocurrency via BeaverTail, InvisibleFerret and other malware.
- · 5d agoContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The Hacker News· 82
North Korea's Contagious Interview campaign hit 30,000 devices and stole about $10.71 million in crypto.
- · 5d agoContagious Interview: 30,000 devices infected by a fake job interview
Security Affairs· 84