CRBC News
Security

North Korean 'WaterPlum' Hackers Infected 30,000+ Devices, Routed ~$10.7M in Crypto to Pyongyang

North Korean 'WaterPlum' Hackers Infected 30,000+ Devices, Routed ~$10.7M in Crypto to Pyongyang
North Korean hackers infected 30,000 devices worldwide by posing as tech recruiters hero image

A joint advisory says North Korea-linked group WaterPlum infected at least 30,000 devices across 100+ countries from December 2025 to July 2026 and routed roughly ¥1.7 billion (~$10.7M) in cryptocurrency to Pyongyang. The campaign targeted developers, designers and blockchain specialists using fake job interviews and poisoned code repositories to deploy malware that stole wallet credentials, passwords and identity documents. Authorities link WaterPlum to North Korea's 313 General Bureau and to a broader fraudulent IT-worker scheme; Japan also dismantled a domestic "laptop farm."

A joint law-enforcement and intelligence advisory reports that the North Korean threat group known as WaterPlum infected at least 30,000 devices across more than 100 countries and diverted roughly ¥1.7 billion (about $10.7 million) in stolen cryptocurrency to Pyongyang.

The campaign ran from December 2025 through July 2026 and specifically targeted professionals in software development, web design, and cryptocurrency, blockchain and Web3 technologies. According to the advisory, attackers either siphoned funds or captured credentials from more than 7,000 cryptocurrency wallets.

How the Operation Worked

WaterPlum actors posed as prospective employers on social media, job boards, gig platforms and freelance marketplaces. During fake technical interviews and coding tests, targets were instructed to download files hosted on software development platforms or code repositories. Those files were laced with malware that provided remote backdoor access to victims' machines.

Once installed, the malware harvested browser-saved passwords, cryptocurrency wallet credentials, keystrokes, screenshots and identity documents. Compromised devices could also be used as footholds to reach employer corporate networks — increasing the risk of intellectual property theft and state-sponsored espionage.

Tools and Attribution

The advisory links several malware families to WaterPlum, including:

  • BeaverTail — a JavaScript strain hidden in Node Package Manager (NPM) packages;
  • InvisibleFerret — a Python backdoor;
  • OtterCookie — a JavaScript trojan with remote-access capabilities;
  • OtterCandy — an additional malicious JavaScript tool;
  • StoatWaffle — a modular Node.js framework delivered via booby-trapped Visual Studio Code projects.

Agencies involved in the advisory — including the U.S. Federal Bureau of Investigation (FBI), the Defense Department's Cyber Crime Center, Japan's National Police Agency, and Germany's Federal Intelligence Service — assess that WaterPlum operates under North Korea's 313 General Bureau, a unit subordinate to the Munitions Industry Department of the Workers' Party of Korea.

Overlap With Fraudulent IT-Worker Scheme And Domestic Laptop Farm

Investigators identified operational overlap between WaterPlum and North Korea's broader fraudulent IT worker scheme, noting shared IP addresses. Some operators simultaneously performed legitimate web development work for clients while running cyberattacks. Stolen personal identification documents were reportedly reused by North Korean IT workers to impersonate victims when applying for jobs.

Japan's National Police Agency said it located and dismantled a domestic "laptop farm" — a facility of remotely controlled computers — and discovered records indicating several hundred million yen had been moved out of the country as part of the scheme.

What Affected Individuals Should Do

Recommended actions for potentially affected users include: update and patch software; avoid running untrusted code or files received during interviews; enable multi-factor authentication and use hardware wallets where possible; change passwords stored in browsers and review connected crypto wallets; and notify employers and law enforcement if corporate access may be compromised.

"The advisory underscores the continued use of social-engineering and supply-chain techniques to target technical professionals and funnel stolen assets back to state actors."

Help us improve.

Related Articles

Trending