ZeroHour
Story · 2 sources · 3 articlesfirst updated ()

North Korea's WaterPlum fake-recruiter campaign infects 30,000+ devices across 100+ countries, stealing $10.5M–$11M from crypto wallets; nations act on DPRK IT workers

highThreat actorexploited in the wildimportance 80
What's new: First merged summary. New developments: the joint US–Japan–Germany–Australia advisory on WaterPlum was published 2026-09-18; Japanese police dismantled a DPRK laptop farm for the first time; the US-led MSMT released a report following up on the UN's October IT-worker scheme report; and Argentina, Pakistan, Vietnam, Laos, and China took new legal action against alleged facilitators or workers.…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint FBI, DoD, Japanese, German, and Australian advisory attributes the WaterPlum (Contagious Interview) campaign to North Korea's 313 General Bureau, which posed as AI and crypto recruiters to infect 30,000+ devices in over 100 countries between December…

A joint advisory from the FBI, the US Defense Department (including the DoD Cyber Crime Center), Japan's National Police Agency, and German and Australian agencies details 'WaterPlum' (tracked by CyberScoop as Contagious Interview), attributed to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea. Between December 2025 and July 2026, actors posing as recruiters from fake AI, blockchain, cryptocurrency, and NFT companies contacted web designers, software developers, engineers, and crypto specialists via social media and freelance portals, instructing them to download files during interviews. This infected at least 30,000 devices in more than 100 countries with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware plus remote management tools that maintained long-term access. The Record reports over $10.5 million stolen from about 7,000 cryptocurrency wallets, while CyberScoop cites roughly $11 million transferred from more than 7,000 wallets to North Korea. The campaign substantially overlaps with DPRK IT-worker laptop-farm schemes, sharing IP addresses and infrastructure; Japanese police dismantled a laptop farm for the first time, and the FBI is prosecuting US-based facilitators. Separately, the US-led Multilateral Sanctions Monitoring Team (MSMT) released a report tracking global legal responses to North Korea's illicit IT worker scheme, which uses stolen or purchased identities to place workers in high-paying IT jobs: Argentina opened an investigation and froze the assets of alleged money launderer Antonia Doroganova; Pakistan opened a case against alleged forger Syeda Aliya Batool Zaidi and two facilitators; Vietnam and Laos took steps including sanctions and investigations; and China increased surveillance, arresting one IT worker for allegedly stealing military secrets. North Korean overseas workers generated up to $800 million last year, and roughly 100,000 workers remain in at least 17 countries.

  • WaterPlum attributed to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea (advisory partners: FBI, DoD Cyber Crime Center, Japan's National Police Agency, Germany, Australia)
  • At least 30,000 devices infected across 100+ countries between December 2025 and July 2026
  • Funds stolen: over $10.5 million from about 7,000 crypto wallets per The Record; roughly $11 million from more than 7,000 wallets per CyberScoop
  • Malware deployed: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, plus remote management tools for long-term access
  • Victims targeted as job seekers via social media and freelance portals by fake AI, blockchain, crypto, and NFT recruiters, mostly web designers, engineers, and crypto specialists
  • Campaign overlaps with DPRK IT-worker laptop-farm operations, sharing IP addresses and infrastructure
  • Japanese police dismantled a laptop farm for the first time; FBI prosecuting US-based facilitators
  • MSMT report: Argentina investigated and froze assets of Antonia Doroganova; Pakistan opened a case against Syeda Aliya Batool Zaidi and two facilitators; Vietnam and Laos took sanctions and investigative steps; China arrested one IT worker…

Coverage timeline

  1. · 16h ago
    The Record· 80
    North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

    FBI and Japanese police advisory ties North Korea's WaterPlum campaign to $10.5M stolen from job seekers via fake-recruiter malware on 30,000 devices.

  2. · 6h ago
    The Record· 50
    Nations take action on North Korean IT workers after UN report

    Multiple countries took legal action against North Korean IT worker facilitators following a new UN-linked MSMT report on the illicit scheme.

  3. · 4h ago
    CyberScoop· 78
    International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

    US, Japanese, German, and Australian agencies warn North Korea's WaterPlum gang poses as recruiters, infecting 30,000+ devices and stealing about $11 million in crypto.