Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2948+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide
North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide
NEWS

North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide

A joint law enforcement advisory says DPRK-linked WaterPlum hackers compromised 30,000 devices and stole $10.7M in crypto via fake job interviews.

Dylan H.

News Desk

September 20, 2026
3 min read

Joint Advisory Reveals Scale of DPRK Campaign

A joint law enforcement advisory from authorities in Japan, the United States, Australia, and Germany has revealed that the North Korean hacking group WaterPlum compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026, transferring more than $10.7 million in stolen cryptocurrency to North Korea.

According to the advisory, WaterPlum actors moved 1.7 billion Japanese yen — roughly $10.71 million USD — in cryptocurrency assets to the Democratic People's Republic of Korea, drained from over 7,000 compromised cryptocurrency wallets.


The "Contagious Interview" Playbook

WaterPlum is linked to a long-running campaign tracked as Contagious Interview, which has previously used malicious npm packages to infect job seekers' devices. The group impersonates legitimate AI, cryptocurrency, and NFT companies, or poses as recruiters on freelance and job platforms, to draw in targets — primarily web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.

During fake interviews and coding tests, victims are instructed to:

  • Download a "project" or take-home coding assignment
  • Troubleshoot a supposed video-conferencing problem
  • Execute code as part of a technical evaluation

Each of these steps is a delivery mechanism for malware.


Malware Arsenal

MalwareTypeFunction
BeaverTailJavaScriptConcealed in malicious npm packages
InvisibleFerretPythonBackdoor for persistent access
OtterCookieJavaScriptRemote-access trojan and information stealer
OtterCandyHybridCombines OtterCookie and RAT capabilities
StoatWaffleNode.jsModular malware delivered via malicious VS Code project configs that auto-execute on folder trust

Once installed, this toolkit harvests browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, documents, and periodic screenshots.


A State-Directed Operation

Authorities assess that WaterPlum actors, along with some North Korean IT workers operating abroad, function under North Korea's Munitions Industry Department. In a related development, police also shut down the country's first known domestic "laptop farm," where local facilitators hosted computers in their homes while North Korean operators controlled them remotely — posing as Japanese residents to win freelance contracts. Shared IP infrastructure tied the laptop farm directly to the WaterPlum hacking activity.

The official tally in this advisory dwarfs prior independent research: one researcher who spent 22 months inside the group's infrastructure had previously mapped only 1,640 victims across 57 countries — about 18 times smaller than the numbers now confirmed by law enforcement.


Protecting Against Fake Interview Attacks

  1. Never run code from an unsolicited "interview assignment" outside an isolated VM or sandboxed environment
  2. Verify recruiter identities independently through official company channels before proceeding with technical exercises
  3. Avoid granting "trust this workspace" prompts in VS Code or similar editors for unfamiliar repositories
  4. Isolate cryptocurrency wallets and seed phrases from general-purpose development machines
  5. Audit npm packages pulled in as part of take-home assignments before execution
  6. Treat "fix your video call" instructions during interviews as a major red flag

Related Reading

  • ZeroDayRAT Mobile Spyware Enables Total Surveillance of iOS
  • UNC4899 North Korea Crypto Airdrop Trojanized
  • New Jersey Men Given Lengthy Sentences for Running North Korean Laptop Farms
#North Korea#WaterPlum#Cryptocurrency Theft#State-Sponsored#Social Engineering

Related Articles

FBI Warns of North Korean 'WaterPlum' Campaign Infecting Devices Across 100 Countries

FBI, DoD, and allied agencies detail 'WaterPlum,' a North Korean fake-recruiter scheme that stole $10.5M and infected 30,000+ devices.

3 min read

Drift $280M Crypto Theft Linked to 6-Month In-Person DPRK

Drift Protocol has revealed that the $280 million hack it suffered was the culmination of a six-month long operation in which North Korean-linked threat...

5 min read

Crypto Infrastructure Company Blames $290 Million Theft on North Korean Hackers

A major cryptocurrency infrastructure company has attributed a $290 million theft to North Korean state-sponsored hackers, as the industry continues to...

4 min read
Back to all News