North Korea's WaterPlum fake-recruiter campaign infects 30,000+ devices across 100+ countries, stealing $10.5M–$11M from crypto wallets; nations act on DPRK IT workers
A joint FBI, DoD, Japanese, German, and Australian advisory attributes the WaterPlum (Contagious Interview) campaign to North Korea's 313 General Bureau, which posed as AI and crypto recruiters to infect 30,000+ devices in over 100 countries between December…
A joint advisory from the FBI, the US Defense Department (including the DoD Cyber Crime Center), Japan's National Police Agency, and German and Australian agencies details 'WaterPlum' (tracked by CyberScoop as Contagious Interview), attributed to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea. Between December 2025 and July 2026, actors posing as recruiters from fake AI, blockchain, cryptocurrency, and NFT companies contacted web designers, software developers, engineers, and crypto specialists via social media and freelance portals, instructing them to download files during interviews. This infected at least 30,000 devices in more than 100 countries with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware plus remote management tools that maintained long-term access. The Record reports over $10.5 million stolen from about 7,000 cryptocurrency wallets, while CyberScoop cites roughly $11 million transferred from more than 7,000 wallets to North Korea. The campaign substantially overlaps with DPRK IT-worker laptop-farm schemes, sharing IP addresses and infrastructure; Japanese police dismantled a laptop farm for the first time, and the FBI is prosecuting US-based facilitators. Separately, the US-led Multilateral Sanctions Monitoring Team (MSMT) released a report tracking global legal responses to North Korea's illicit IT worker scheme, which uses stolen or purchased identities to place workers in high-paying IT jobs: Argentina opened an investigation and froze the assets of alleged money launderer Antonia Doroganova; Pakistan opened a case against alleged forger Syeda Aliya Batool Zaidi and two facilitators; Vietnam and Laos took steps including sanctions and investigations; and China increased surveillance, arresting one IT worker for allegedly stealing military secrets. North Korean overseas workers generated up to $800 million last year, and roughly 100,000 workers remain in at least 17 countries.
- WaterPlum attributed to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea (advisory partners: FBI, DoD Cyber Crime Center, Japan's National Police Agency, Germany, Australia)
- At least 30,000 devices infected across 100+ countries between December 2025 and July 2026
- Funds stolen: over $10.5 million from about 7,000 crypto wallets per The Record; roughly $11 million from more than 7,000 wallets per CyberScoop
- Malware deployed: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, plus remote management tools for long-term access
- Victims targeted as job seekers via social media and freelance portals by fake AI, blockchain, crypto, and NFT recruiters, mostly web designers, engineers, and crypto specialists
- Campaign overlaps with DPRK IT-worker laptop-farm operations, sharing IP addresses and infrastructure
- Japanese police dismantled a laptop farm for the first time; FBI prosecuting US-based facilitators
- MSMT report: Argentina investigated and froze assets of Antonia Doroganova; Pakistan opened a case against Syeda Aliya Batool Zaidi and two facilitators; Vietnam and Laos took sanctions and investigative steps; China arrested one IT worker…
Coverage timelineoldest first · each row is one article
- · 16h agoNorth Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The Record· 80
FBI and Japanese police advisory ties North Korea's WaterPlum campaign to $10.5M stolen from job seekers via fake-recruiter malware on 30,000 devices.
- · 6h agoNations take action on North Korean IT workers after UN report
The Record· 50
Multiple countries took legal action against North Korean IT worker facilitators following a new UN-linked MSMT report on the illicit scheme.
- · 4h agoInternational security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
CyberScoop· 78
US, Japanese, German, and Australian agencies warn North Korea's WaterPlum gang poses as recruiters, infecting 30,000+ devices and stealing about $11 million in crypto.