The North Korean hacking group WaterPlum has infected at least 30,000 devices worldwide in attacks on software developers and other IT professionals and transferred nearly US$11mil (RM44.8mil) in stolen cryptocurrency to the country.
The hacks occurred from December 2025 through July 2026, according to a joint cybersecurity advisory issued on Sept 18 by Japanese, Australian, German, and US authorities, including the Federal Bureau of Investigation and the Defense Department’s Cyber Crime Center.
WaterPlum, also known as Contagious Interview, has obtained money or account credentials from more than 7,000 cryptocurrency wallets and transferred cryptocurrency worth 1.7bil yen, or about US$10.7mil (RM43.6mil), to North Korea, officials said.
The group reportedly has been active since 2023, carrying out both financially motivated attacks and cyberespionage.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies said in a statement. “They often impersonate legitimate artificial intelligence, cryptocurrency or non-fungible token companies and have also used recruiting services.”
The hackers lure job seekers through social media, online job platforms, gig-work sites, and freelance marketplaces. WaterPlum asks responders to take part in virtual technical interviews or complete coding assignments. The attackers then instruct targets to download and run malicious files, sometimes under the guise of completing an assignment or troubleshooting a problem with videoconferencing software.
Once the group gains access to a device or network, it uses malware to steal information, including browser passwords, screenshots, files, and cryptocurrency-wallet data. An infected computer can also provide an avenue into the network of the target’s employer, opening the door to intellectual-property theft and espionage, authorities said.
The operation overlaps with a separate scheme in which North Korean nationals conceal their identities and locations to obtain remote IT work with companies abroad, officials said.
Investigators found that WaterPlum and the fraudulent IT workers used the same IP addresses to access crowdsourcing services and “laptop farms,” setups that disguise where workers are actually based. The same addresses were also used in applications for positions at a Japanese cryptocurrency exchange.
The international agencies advise all companies that work with IT professionals to remain vigilant. “Actors continuously evolve and refine their methods,” officials said in the report. “Stay informed by monitoring alerts from domestic and international security agencies and by reviewing reports published by security vendors.” – Inc./Tribune News Service
