WaterPlum cyber campaign hit 30,000 devices across 100 countries

,
 September 20, 2026

North Korea-linked WaterPlum hackers infected at least 30,000 devices and sent $10.71 million in cryptocurrency to the regime, authorities warned.

A joint advisory from Japanese, American, Australian, and German authorities traced the reported activity from December 2025 through July 2026. The infections reached devices in more than 100 countries.

The campaign targeted people through job searches, recruiting contacts, freelance work, coding tests, and fake interviews. It turned ordinary hiring tools into paths for malware, stolen credentials, and cryptocurrency theft.

Authorities linked WaterPlum to a multi-year campaign called “Contagious Interview.” The group allegedly used malicious coding projects and software packages to compromise job seekers and technology workers.

BleepingComputer reported that the advisory placed the operation’s reach and financial damage in stark terms:

“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,”

Fake interviews gave WaterPlum a path into thousands of devices

WaterPlum’s approach relied on familiar professional settings. Attackers allegedly approached targets through job-seeking, recruiting, and freelance platforms, then directed them toward malicious interviews or coding exercises.

Those exercises included harmful Visual Studio Code projects and malicious npm packages. Npm packages are bundles of reusable software code that developers can add to their projects.

Running the wrong project could install additional malware. The advisory linked five malware families to WaterPlum operations: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

The attack method exploited a basic pressure point in modern hiring. Applicants expect coding tests, file downloads, and requests to run sample projects. WaterPlum allegedly hid its tools inside that routine.

Once attackers gained access, authorities said they stole funds or account credentials from more than 7,000 cryptocurrency wallets. The unnamed victims included device users and cryptocurrency-wallet holders around the world.

Authorities say $10.71 million reached North Korea

The advisory said WaterPlum transferred 1.7 billion Japanese yen in cryptocurrency assets to North Korea. Authorities valued that amount at $10.71 million.

The campaign was not described as theft for its own sake. The reported financial attacks created revenue for the North Korean regime and helped fund its weapons programs.

The FBI and Japanese police assessed that WaterPlum actors and some North Korean information-technology workers operate under the country’s 313 General Bureau. The precise evidence behind that assessment was not disclosed.

Japan’s National Police Agency also identified, investigated, and dismantled a North Korean IT-worker “laptop farm” in Japan. Investigators found evidence that several hundred million yen had been transferred abroad in connection with that operation.

The location of the laptop farm was not identified. Authorities also did not disclose whether the investigation produced arrests or prosecutions.

Companies were told to verify workers before granting access

The joint advisory urged employers to check job applicants’ identities, locations, and qualifications. It also advised companies to limit each worker’s access to only the systems and data needed for the job.

That guidance addresses both parts of the threat. WaterPlum allegedly used fake recruitment activity to deliver malware, while North Korean IT workers could seek access through employment itself.

Developers received a separate warning: Do not run unknown code outside a sandbox. A sandbox is an isolated environment that keeps untrusted software away from the rest of a computer or network.

Authorities also told developers to inspect unfamiliar files and code for commands that download more software. Those hidden instructions can turn a seemingly limited coding test into a wider compromise.

Basic controls matter because access granted during hiring can reach valuable systems. Identity checks, narrow permissions, and isolated testing make it harder for a false applicant or tainted project to open that door.

Key questions remain after a campaign spanning 100 countries

The advisory supplied broad totals but did not name the affected people, businesses, devices, or cryptocurrency wallets. It also did not provide the dates of individual infections or transfers.

That leaves victims without a public list they can check. It also limits outside scrutiny of how attackers moved money and which organizations failed to stop them.

The known figures are still substantial: at least 30,000 compromised devices, more than 7,000 affected wallets, and over $10.7 million transferred to North Korea. All of that allegedly occurred within an eight-month period.

The campaign shows why hiring cannot rest on polished profiles and plausible technical requests. Employers must treat identity, access, and unfamiliar code as security questions from the first contact.

Trust is not a substitute for verification, especially when hostile regimes have learned how to profit from it.

About Alex Tanzer

Become Wealthier... 
In Just 5 Minutes Per Day

Subscribe to Capital Digest and get fast, actionable insights on markets, money, and opportunity — straight to your inbox.