Skip to main content
Emerging ThreatsMalware & Ransomware

North Korean Hackers Infect 30,000 Devices in Global Campaign

Travelers walk near a public area in a brightly-lit airport terminal, conveying global connectivity and vulnerability.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," reads a joint law enforcement advisory from Japanese, U.S., Australian, and German authorities.

The advisory traces a multi-year, financially motivated campaign attributed to the North Korean-linked group known as WaterPlum. According to the agencies, the activity — tracked from December 2025 through July 2026 — resulted in at least 30,000 compromised devices worldwide and the transfer of 1.7 billion Japanese yen (JPY), equivalent to 10.71 million USD, in cryptocurrency to the Democratic People’s Republic of Korea (DPRK).

WaterPlum and the "Contagious Interview" recruitment ruse

The advisory links WaterPlum to a campaign the agencies call "Contagious Interview," which targets job seekers by impersonating legitimate companies in AI, cryptocurrency, and NFTs, or by leveraging recruiting and freelance platforms. Attackers approach candidates for interviews and coding tests and then instruct targets to download projects, troubleshoot supposed video-conferencing issues, or execute code — actions that introduce malicious software into victims’ environments.

Malware families the advisory ties to WaterPlum

  • BeaverTail: JavaScript malware concealed in npm packages.
  • InvisibleFerret: A Python-based backdoor.
  • OtterCookie: A JavaScript remote-access trojan (RAT) and information stealer.
  • OtterCandy: Malware that combines OtterCookie and RAT capabilities.
  • StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.

The advisory describes these tools as designed to harvest credentials and secrets, and to give attackers persistent access once a system is compromised.

Operational tradecraft: credentials, pivots, and identity abuse

Once installed, the tools aim to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, documents, and screenshots. The agencies warn attackers may use access to an infected machine to pivot into employers’ or clients’ networks, expanding the operation from fraud and theft into intellectual property theft and potential espionage.

Investigators also found operational practices intended to defeat live verification: WaterPlum actors use AI face‑swapping software during online interviews, then turn off their cameras and blame network problems. The advisory states North Korean IT workers linked to the same operations have reused identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.

State links, financial flows, and a Japanese "laptop farm" takedown

The advisory connects WaterPlum and some associated North Korean IT workers to North Korea’s 313 General Bureau, part of the Munitions Industry Department. Law enforcement collectively traced the group’s activity across more than 100 countries, identified exfiltration from over 7,000 cryptocurrency wallets, and documented transfers of 1.7 billion JPY to the DPRK.

Japan’s National Police Agency reported that authorities identified, investigated, and dismantled a North Korean IT-worker "laptop farm" in the country, finding evidence that several hundred million yen had been transferred abroad as part of those operations.

What this means for developers, employers, and cryptocurrency users

  • Developers and security teams: The advisory urges avoiding running unknown code outside a sandbox and carefully inspecting provided files and code for commands that fetch additional payloads—precisely the vectors the BeaverTail and StoatWaffle techniques exploit.
  • Employers and hiring managers: The advisory warns companies to verify applicants’ identities, locations, and qualifications and to restrict new hires’ access to only the systems and data required to perform their jobs — steps aimed at limiting the pivot and impersonation risks the advisory describes.
  • Cryptocurrency holders and services: With more than 7,000 wallets identified as having had funds or credentials exfiltrated, the advisory underscores that attackers are targeting private keys and seed phrases directly and monetizing those thefts via transfers to the DPRK.

The joint advisory paints a coordinated picture: social engineering framed as recruitment, software supply‑chain and developer-tool abuse, credential and seed‑phrase theft, and financial laundering channels that move proceeds to the DPRK. The agencies’ specific figures — at least 30,000 infected devices, over 7,000 wallets impacted, and 1.7 billion JPY moved to the DPRK — make clear the scale of the campaign and the concrete mitigations they recommend: rigorous identity verification, least-privilege access controls, sandboxing unknown code, and careful inspection of supplied projects and configuration files.

Read the original advisory and reporting at BleepingComputer.