North Korean hacking group WaterPlum compromises 30,000 devices and siphons over $10 million in global cryptocurrency theft campaign

In a coordinated international effort, law enforcement agencies from the United States, Japan, Australia, and Germany have issued a comprehensive advisory detailing the extensive reach of the North Korean state-sponsored threat actor known as "WaterPlum." Operating under the guise of legitimate business activity, the group has successfully compromised at least 30,000 devices across more than 100 countries between December 2025 and July 2026. According to the multi-national intelligence findings, this campaign facilitated the illicit transfer of approximately $10.7 million in cryptocurrency, proceeds that investigators assert are being funneled directly into the Democratic People’s Republic of Korea (DPRK) to bolster the regime’s illicit weapons and ballistic missile programs.
The advisory marks a significant escalation in the public attribution of North Korean cyber-espionage. By linking WaterPlum—also identified in security circles as the group behind the "Contagious Interview" campaign—to the broader administrative apparatus of the North Korean government, international authorities are highlighting a sophisticated, multi-faceted threat that targets both individual IT professionals and corporate infrastructure.
The Anatomy of the Contagious Interview Campaign
The "Contagious Interview" campaign represents a highly evolved form of social engineering. Rather than relying solely on traditional phishing vectors, WaterPlum actors embed themselves into the professional ecosystem. The threat actors create elaborate facades, posing as representatives from legitimate AI, cryptocurrency, and NFT-focused companies. They leverage mainstream freelance and recruitment platforms to identify and approach job seekers, particularly those in the software development and IT sectors.

Once a target has been engaged, the attackers initiate a rigorous interview process. During these staged interactions, which often involve technical coding tests, the victim is directed to download project files or troubleshoot "video-conferencing connectivity issues." These actions are designed to bypass standard security protocols. By convincing the applicant to execute malicious code under the guise of testing their technical proficiency, the hackers gain initial access to the victim’s machine.
Investigators noted a chilling level of sophistication in these operations: the hackers frequently employ AI-powered face-swapping software during video interviews. If the software glitches or the victim becomes suspicious of the video quality, the attackers routinely terminate the camera feed, blaming network latency or technical infrastructure problems to maintain their cover.
Chronology of the 2025-2026 Campaign
The timeline of WaterPlum’s activity suggests a sustained, high-intensity operation:
- December 2025: Initial signs of a surge in malicious npm packages targeting job seekers appear. The packages are designed to exfiltrate data upon execution.
- January – March 2026: WaterPlum expands its presence on freelance platforms, focusing on high-value targets with access to corporate networks.
- April – June 2026: The campaign reaches its peak efficiency. Intelligence agencies observe a sharp increase in the transfer of stolen cryptocurrency wallets. During this period, the group begins pivoting from individual devices to the internal networks of the employers of their victims.
- July 2026: The conclusion of the primary data collection phase for the joint law enforcement advisory. The total tally of compromised devices reaches the 30,000 mark.
- September 2026: Official advisories are published simultaneously by the FBI (USA), the National Police Agency (Japan), the Australian Cyber Security Centre, and the German Federal Office for the Protection of the Constitution.
Financial Impact and State Sponsorship
The $10.7 million in cryptocurrency represents only the direct, traceable losses. The broader economic impact, including intellectual property theft and the costs associated with incident response, remains incalculable. The funds were siphoned from over 7,000 cryptocurrency wallets, with the proceeds laundered through various tumblers to mask their destination before eventually arriving in North Korea.

Perhaps more concerning to security analysts is the connection to North Korea’s "IT worker" program. Evidence indicates that WaterPlum hackers are not merely conducting espionage; they are also operating as remote, "hired" IT contractors. By using identity documents stolen from their victims, these operatives secure legitimate employment at companies worldwide. They then perform web development and IT maintenance work, earning a salary for the North Korean regime while simultaneously using their access to exfiltrate sensitive data.
The FBI and Japanese authorities have explicitly linked both WaterPlum and these remote IT worker cells to the 313 General Bureau. This bureau operates under the Munitions Industry Department, the very entity responsible for the research and production of North Korea’s weapons of mass destruction. The implication is clear: the modern corporate IT department has, in some cases, become an involuntary financier of state-level weapons development.
The "Laptop Farm" Discovery
A landmark development in this investigation occurred in Japan, where the National Police Agency dismantled a clandestine "laptop farm." This facility served as a hub for North Korean IT workers, allowing them to manage multiple concurrent remote jobs from a single physical location. By centralizing operations, the hackers were able to maintain high levels of output, contributing to the millions of yen in illicit revenue that was eventually repatriated to the DPRK. This discovery provides the first physical proof of the scale of the "remote worker" infrastructure that has been plaguing global human resources departments for years.
Strategic Implications and Defense Recommendations
The persistence of the WaterPlum threat underscores the need for a shift in corporate cybersecurity culture. Security agencies are emphasizing that traditional endpoint protection is no longer sufficient when employees are being socially engineered into executing malicious files themselves.

Recommended mitigation strategies include:
- Identity Verification: Companies must move beyond basic background checks. Verifying the physical location and true identity of remote contractors is now a business-critical requirement.
- Strict Sandboxing: Developers should never execute project code or build tools on primary workstations. All unverified code must be run in an isolated, non-persistent environment or a secure sandbox.
- Principle of Least Privilege: Employees, especially those working remotely, should only have access to the specific repositories and cloud environments required for their immediate tasks.
- Endpoint Monitoring: Security teams must monitor for unauthorized connections to known "tumbler" services or cryptocurrency exchanges, which are common indicators of a compromised machine.
Analysis: A New Frontier in Cyber-Warfare
The WaterPlum campaign represents a departure from traditional "smash and grab" cyber-attacks. By leveraging the modern remote-work culture, North Korean actors have effectively weaponized the hiring process. This "long-con" approach, which combines technical malware execution with long-term impersonation, provides the DPRK with a dual-income stream: the direct theft of assets and the salary earned through legitimate-looking IT work.
For global security experts, the challenge lies in the decentralized nature of the workforce. As long as companies prioritize rapid hiring and remote flexibility without implementing rigorous technical verification for incoming developers, the door remains open for state-sponsored actors to infiltrate the supply chain. The joint advisory serves as a warning that the "Contagious Interview" is not just a security incident, but a systemic challenge to the integrity of the global digital economy.
As the international community grapples with these revelations, the focus is shifting toward stricter regulatory requirements for tech hiring and a greater emphasis on "zero-trust" architectures. Whether these measures will be enough to stem the tide of North Korean cyber-aggression remains to be seen, but the clear link between a developer’s laptop and a munitions factory has irrevocably changed the stakes of corporate cybersecurity.







