Joint Advisory: North Korea’s ‘WaterPlum’ Hackers Infected 30,000 Devices Through Fake Job Interviews

A joint law-enforcement advisory says North Korea’s WaterPlum group infected at least 30,000 devices in more than 100 countries by posing as recruiters, stealing more than $10 million in cryptocurrency.

Abstract illustration of a shield with a padlock over a grid of digital squares
Illustration: GlobePrism

The short version

  • Authorities in the US, Japan, Australia and Germany say the North Korean group WaterPlum infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026.
  • Victims were tricked during fake job interviews into downloading malicious projects. Funds or credentials were taken from over 7,000 cryptocurrency wallets, and about $10.7 million was sent to North Korea.
  • The operation is linked to North Korea’s fake IT-worker schemes, and investigators say the hackers used AI face-swapping software in video interviews.
  • The advisory tells employers to verify applicants and tells developers never to run unknown code outside a sandbox.

Why it matters: The campaign targets ordinary job seekers and developers, and can turn one infected laptop into a way into a company’s network. It also funds a government’s weapons programmes, according to the agencies.

On this page
  1. How the scam works
  2. The link to fake IT workers
  3. A repeating pattern
  4. What the agencies recommend

One of the most persistent state-backed hacking campaigns in the world works by pretending to offer you a job. A joint advisory published on Friday 18 September by authorities in Japan, the United States, Australia and Germany says North Korea’s WaterPlum hackers infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, and moved more than $10 million in stolen cryptocurrency to the regime in Pyongyang.

  • 30,000+Devices infected in 100+ countries
  • 7,000+Crypto wallets drained or credentials taken
  • $10.7mCrypto sent to North Korea (¥1.7 billion)
  • Dec 2025–Jul 2026Period covered by the advisory

How the scam works

WaterPlum is linked to a long-running campaign known as “Contagious Interview”. The attackers impersonate genuine AI, cryptocurrency and NFT companies, or approach people through social media, gig-work websites and freelance platforms. The main targets are web designers, engineers and cryptocurrency specialists, and IT professionals in Japan and elsewhere have been hit.

During a fake interview or coding test, the candidate is asked to download a project, fix a supposed video-conferencing fault, or run some code. That code is malware. The advisory names several families used by the group, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Some are hidden in npm packages, and StoatWaffle is delivered through malicious Visual Studio Code projects that run commands as soon as a folder is opened and trusted.

Once inside, the attackers try to steal browser passwords, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, documents and screenshots. They also try to stay on the machine so they can move into the victim’s employer or client networks, which can lead to theft of intellectual property and espionage, BleepingComputer reported.

The agencies say WaterPlum is closely tied to North Korea’s schemes in which IT workers obtain remote jobs at technology firms under false identities. Some WaterPlum hackers also work as remote web developers, and the two groups have used the same IP addresses. Identity documents stolen from WaterPlum victims are reused by other North Korean workers to impersonate those people and get hired. Investigators also found that the operators used AI face-swapping software during online interviews, then switched off their cameras and blamed network problems.

The FBI and Japanese police assess that WaterPlum and some IT workers operate under North Korea’s 313 General Bureau, part of the Munitions Industry Department that oversees weapons research and production. Japan’s National Police Agency said it identified, investigated and dismantled a North Korean IT-worker “laptop farm” in Japan for the first time, and found that several hundred million yen had been sent abroad.

A repeating pattern

The Record noted that in April, incident responders found a similar campaign using the same malware strains in which up to $12 million in cryptocurrency was stolen, aimed at blockchain developers contacted by fake recruiters on LinkedIn. Cybersecurity firms have tracked North Korean job-seeker campaigns since 2020, including efforts against people in the defence industry.

What the agencies recommend

  • Employers: carefully verify job applicants’ identities, locations and qualifications, and limit new hires’ access to only the systems and data they need.
  • Developers: avoid running unknown code outside a sandbox, and inspect any files you are given for commands that download extra programs.
  • Job seekers, in general: be suspicious of recruiters who reach out unprompted, insist on a video call that needs a special download, or ask you to run a test project on the same computer that holds your work accounts or crypto wallets. Verify the company and the recruiter through its official website before you engage.

If you think you have run suspicious code, disconnect the device from the internet, change your passwords and move any cryptocurrency from a different, clean device, and report it to your national cybercrime authority.

Sources and further reading

  1. North Korean WaterPlum hackers infected 30,000 devices worldwide — BleepingComputer , 2026-09-19
  2. North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign — The Record , 2026-09-18

This article was written by our newsdesk from the public reporting linked above. How we report

Frequently asked questions

What is WaterPlum?

WaterPlum is the name authorities use for a North Korean hacking group that targets job seekers, developers and crypto users. It is linked to the “Contagious Interview” campaign and to North Korea’s fake IT-worker operations.

How can I tell if a recruiter is fake?

Warning signs include unsolicited contact, pressure to move quickly, a requirement to install unfamiliar software for a “test”, and a company that you cannot verify on its official website. Check the recruiter’s identity independently before you respond.

Which agencies issued the advisory?

Japan’s National Police Agency and law-enforcement authorities in the United States (including the FBI and the Department of Defense), Australia and Germany, according to the reporting.