
A recent report from law enforcement and intelligence agencies in the US, Japan, Australia, and Germany reveals that a group linked to North Korea, called “WaterPlum,” has hacked over 30,000 devices across 100 countries, stealing at least $10.7 million (about ¥1.7 billion) in cryptocurrency.
The hacking campaign, tracked globally by cybersecurity researchers with the name “Contagious Interview,” took place from December 2025 to July 2026. It targeted software engineers, Web3 developers, and others in tech jobs through fake job postings.
The WaterPlum group pretends to be “tech recruiters” using social media and freelance sites to attract skilled workers. They lure victims into accepting high-paying jobs with fake AI or cryptocurrency companies. Once someone has been tricked into applying, the attackers use two main methods to compromise their computers:
- Malicious Coding Tests: After getting hired, victims receive technical tasks that seem legitimate. While working on these tasks, they unknowingly download harmful JavaScript packages. When these packages run on their computers, they install trojans.
- Manipulated Video Calls: During the interview, victims may join an online video call where their camera or microphone appears to malfunction. When asked to install “troubleshooting scripts,” they unintentionally give attackers access to their computers.
After getting in, the malware (named BeaverTail, InvisibleFerret, and StoatWaffle) collects passwords, keystrokes, remote session tokens, and private keys from over 7,000 cryptocurrency wallets.
Connections to State Intelligence and Laptop Farms
The advisory notes that investigators have found clear links to North Korea’s 313 General Bureau, a cyber unit linked to their Munitions Industry Department. It adds:
- WaterPlum’s malware operations share similarities with North Korea’s broader schemes to deceive IT workers.
- The attackers use the same infrastructure, including identical IP addresses, to manage “laptop farms” in targeted countries.
- Stolen identities and credentials are reused by North Korean operatives to secure remote tech jobs at foreign companies.
Recently, Japanese authorities confirmed the first domestic bust of a North Korea-linked laptop farm, seizing records that show hundreds of millions of yen have been sent to Pyongyang.
