Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2910+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FBI Warns of North Korean 'WaterPlum' Campaign Infecting Devices Across 100 Countries
FBI Warns of North Korean 'WaterPlum' Campaign Infecting Devices Across 100 Countries
NEWS

FBI Warns of North Korean 'WaterPlum' Campaign Infecting Devices Across 100 Countries

FBI, DoD, and allied agencies detail 'WaterPlum,' a North Korean fake-recruiter scheme that stole $10.5M and infected 30,000+ devices.

Dylan H.

News Desk

September 18, 2026
3 min read

A Joint Advisory on a Global Scheme

The FBI and the U.S. Department of Defense, working alongside Japan's National Police Agency and law enforcement in Australia and Germany, have issued a joint advisory detailing "WaterPlum," a North Korean cyber operation that has infected more than 30,000 devices across 100 countries by posing as recruiters for artificial intelligence and blockchain companies.


How the Scheme Works

WaterPlum operators approach job seekers — primarily web designers, engineers, and cryptocurrency specialists — through social media, freelance platforms, and gig-work websites, presenting themselves as recruiters for AI or blockchain startups. During the fake interview process, targets are instructed to download a file, typically framed as a coding test, project brief, or interview tool. That download is the infection vector.

Once installed, the malware harvests credentials and cryptocurrency wallet data from the victim's device. The campaign began by focusing on IT professionals in Japan before expanding its geographic reach.


Scale and Financial Impact

MetricFigure
Devices infected30,000+
Countries affected100
Funds stolen$10.5 million+
Cryptocurrency wallets compromised~7,000
Campaign windowDecember 2025 – July 2026

The Malware Arsenal

Investigators identified five distinct malware families used across the campaign:

MalwareRole
BeaverTailInfostealer / initial loader
InvisibleFerretBackdoor / secondary payload
OtterCookieCredential and data theft
OtterCandyRemote access / management
StoatWafflePersistence and control

A Secondary Objective: Corporate Access

Beyond direct cryptocurrency theft, investigators warn that WaterPlum operators have used stolen identities from victims to apply for and secure real jobs at technology companies — a tactic that echoes the broader North Korean IT-worker infiltration schemes seen in recent years. Where successful, this gives the group a foothold on legitimate corporate networks that goes well beyond the initial financial theft.


Recommendations

The advisory urges job seekers and hiring teams alike to treat unsolicited recruiter contact with caution:

  • Never run downloaded files as part of an interview or "coding test" process on a primary or sensitive device — use an isolated VM or sandbox instead
  • Verify recruiter and company identities independently, outside the messaging platform where contact was initiated
  • Monitor cryptocurrency wallets for unauthorized access following any interview process that involved a download
  • Employers should scrutinize new hires' backgrounds against known WaterPlum/North Korean IT-worker infiltration patterns, particularly for remote roles

Sources

  • The Record — North Korean Hackers Infect Thousands of Devices Across 100 Countries as Part of 'WaterPlum' Scheme
#North Korea#WaterPlum#Cryptocurrency#FBI#Job Scam

Related Articles

North Korean Hackers Use Fake Zoom Meeting to Target Crypto

UNC1069, a North Korean APT group, deployed a sophisticated ClickFix scam using a fake Zoom meeting to target a cryptocurrency executive in a social...

5 min read

Lazarus Hackers Exploited Windows Zero-Day to Target Defense Firms

North Korea's Lazarus Group weaponized CVE-2026-68820 in Operation Dream Job, hitting defense and aerospace firms across four countries for five weeks.

4 min read

North Korean Hackers Target Open Source Developers in Supply Chain Attacks

The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer...

5 min read
Back to all News