A Joint Advisory on a Global Scheme
The FBI and the U.S. Department of Defense, working alongside Japan's National Police Agency and law enforcement in Australia and Germany, have issued a joint advisory detailing "WaterPlum," a North Korean cyber operation that has infected more than 30,000 devices across 100 countries by posing as recruiters for artificial intelligence and blockchain companies.
How the Scheme Works
WaterPlum operators approach job seekers — primarily web designers, engineers, and cryptocurrency specialists — through social media, freelance platforms, and gig-work websites, presenting themselves as recruiters for AI or blockchain startups. During the fake interview process, targets are instructed to download a file, typically framed as a coding test, project brief, or interview tool. That download is the infection vector.
Once installed, the malware harvests credentials and cryptocurrency wallet data from the victim's device. The campaign began by focusing on IT professionals in Japan before expanding its geographic reach.
Scale and Financial Impact
| Metric | Figure |
|---|---|
| Devices infected | 30,000+ |
| Countries affected | 100 |
| Funds stolen | $10.5 million+ |
| Cryptocurrency wallets compromised | ~7,000 |
| Campaign window | December 2025 – July 2026 |
The Malware Arsenal
Investigators identified five distinct malware families used across the campaign:
| Malware | Role |
|---|---|
| BeaverTail | Infostealer / initial loader |
| InvisibleFerret | Backdoor / secondary payload |
| OtterCookie | Credential and data theft |
| OtterCandy | Remote access / management |
| StoatWaffle | Persistence and control |
A Secondary Objective: Corporate Access
Beyond direct cryptocurrency theft, investigators warn that WaterPlum operators have used stolen identities from victims to apply for and secure real jobs at technology companies — a tactic that echoes the broader North Korean IT-worker infiltration schemes seen in recent years. Where successful, this gives the group a foothold on legitimate corporate networks that goes well beyond the initial financial theft.
Recommendations
The advisory urges job seekers and hiring teams alike to treat unsolicited recruiter contact with caution:
- Never run downloaded files as part of an interview or "coding test" process on a primary or sensitive device — use an isolated VM or sandbox instead
- Verify recruiter and company identities independently, outside the messaging platform where contact was initiated
- Monitor cryptocurrency wallets for unauthorized access following any interview process that involved a download
- Employers should scrutinize new hires' backgrounds against known WaterPlum/North Korean IT-worker infiltration patterns, particularly for remote roles