A joint law enforcement advisory from the United States, Japan, Australia, and Germany warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide. The group also transferred more than $10.7 million in stolen cryptocurrency to North Korea. WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime.
What Happened: WaterPlum Infects 30,000 Devices Across 100 Countries
WaterPlum operated a multi-year campaign from December 2025 through July 2026. The threat actors infected at least 30,000 devices in more than 100 countries. They also exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. The stolen assets totaled 1.7 billion Japanese yen, equivalent to approximately $10.71 million USD.
The campaign is linked to a broader operation known as “Contagious Interview.” In this operation, threat actors target job seekers with fake interviews and malicious coding tests. The attackers impersonate legitimate AI, cryptocurrency, and NFT companies. They also use recruiting and freelance platforms to approach victims. During the fake interviews, targets are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.
Technical Details of the WaterPlum Campaign
WaterPlum uses several malware families to compromise targets and maintain persistence. The joint advisory links the following malware to WaterPlum operations:
- BeaverTail: JavaScript malware concealed in npm packages that steals browser credentials and clipboard contents.
- InvisibleFerret: A Python-based backdoor that captures screenshots, logs keystrokes, and exfiltrates documents.
- OtterCookie: A JavaScript remote-access trojan and information stealer.
- OtterCandy: Malware combining OtterCookie capabilities with additional remote access features.
- StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects. It uses configuration files that execute code after a folder is opened and trusted.
Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents. They also capture screenshots. Furthermore, the attackers may use access to infected computers to pivot to employers’ or clients’ networks. This expands the attacks to intellectual property theft and espionage.
Business and Operational Impact
The WaterPlum campaign carries significant consequences for organizations and individuals alike. The following impacts are highlighted in the joint advisory:
- Financial losses: Over $10.7 million in cryptocurrency was transferred to North Korea, directly funding the regime’s weapons programs.
- Credential theft: More than 7,000 cryptocurrency wallets were compromised, exposing private keys and seed phrases.
- Corporate espionage: Access to victim devices enabled lateral movement into employer and client networks.
- Identity fraud: North Korean IT workers reused identity documents stolen in WaterPlum attacks to impersonate victims and obtain remote jobs.
- AI-enabled deception: WaterPlum actors used AI face-swapping software during online interviews, then turned off cameras and blamed network problems.
Mitigation and Recommendations
The FBI, CISA, and international partners recommend immediate actions to defend against WaterPlum and similar campaigns. Organizations should apply the following measures:
Immediate Actions for Defenders
- Verify job applicants’ identities, locations, and qualifications carefully before granting system access.
- Restrict remote worker access to only the systems and data required to perform their jobs.
- Require multi-factor authentication for all remote access and privileged accounts.
- Inspect provided files and code for commands that fetch additional payloads before execution.
- Avoid running unknown code outside a sandboxed environment.
- Monitor for unauthorized npm package installations and anomalous Visual Studio Code extensions.
- Implement endpoint detection and response tools to detect BeaverTail, InvisibleFerret, and related malware.
Long-Term Strategies
Organizations should also adopt longer-term strategies to reduce exposure to supply chain and social engineering attacks. Consequently, security teams should conduct regular phishing and social engineering simulations. Furthermore, developers should use dependency scanning tools to detect malicious npm packages. Finally, organizations should maintain an inventory of all third-party code and extensions used in development environments.
Bottom line: WaterPlum is a large-scale, state-sponsored campaign that blends social engineering, supply chain attacks, and identity fraud. Organizations must verify remote workers rigorously and restrict access to protect sensitive systems and data.
Incident Summary
| Threat Actor: | WaterPlum (North Korea, linked to 313 General Bureau / Munitions Industry Department) |
| Campaign Name: | Contagious Interview |
| Affected Devices: | At least 30,000 devices in 100+ countries |
| Cryptocurrency Wallets Compromised: | Over 7,000 |
| Financial Loss: | ~$10.71 million USD (1.7 billion JPY) |
| Campaign Period: | December 2025 – July 2026 |
| Disclosure Date: | September 18, 2026 |
| Advisory Sources: | FBI, CISA, Japan NPA, Australian Cyber Security Centre, German BfV |
References
- FBI and CISA, “Joint Cybersecurity Advisory: North Korean WaterPlum Cyber Actor Group,” September 18, 2026, https://www.ic3.gov/CSA/2026/260918.pdf.
- Japan National Police Agency, “North Korean WaterPlum Cyber Actor Group Targeting IT Professionals,” September 18, 2026, https://www.npa.go.jp/news/release/2026/20260918001.html.
- Australian Cyber Security Centre, “North Korean WaterPlum Commonly Referred to as Contagious Interview Cyber Actor Group Targeting IT Professionals,” September 18, 2026, https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals.
- German Federal Office for the Protection of the Constitution (BfV), “Joint Cybersecurity Advisory: North Korean WaterPlum,” September 18, 2026, https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-09-18-joint-cybersecurity-advisory.html.
- Bill Toulas, “North Korean WaterPlum hackers infected 30,000 devices worldwide,” BleepingComputer, September 19, 2026, https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/.