TheCyberExpress

WaterPlum Hackers Steal $10.7M Crypto From IT Pros


A North Korean cyber actor group known as WaterPlum, also referred to as “Contagious Interview,” has infected at least 30,000 devices across more than 100 countries. The group has been stealing cryptocurrency from IT professionals worldwide.

A joint advisory was issued on September 18, 2026, by Japan’s National Police Agency and National Cybersecurity Office, the US FBI and Department of Defense Cyber Crime Center, Australia’s Signals Directorate, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution.

How WaterPlum Hackers Operate

The agencies assess that WaterPlum actors and certain North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, part of the Workers’ Party of Korea’s Central Committee. The group poses as prospective employers, targeting software developers and IT professionals by impersonating artificial intelligence, cryptocurrency, or non-fungible token companies, and by using recruiting services.

During fake technical interviews, victims are instructed to download files to complete coding assignments or fix errors on video calls. These files carry malicious Node Package Manager packages embedded with BeaverTail malware, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle. Once installed, the malware grants backdoor access, allowing Remote Access Trojans to maintain persistence while infostealers exfiltrate wallet credentials, browser passwords, clipboard data, keystrokes, and identification documents to command-and-control servers.

Scale of the Cryptocurrency Theft

Between December 2025 and July 2026, WaterPlum exfiltrated funds or credentials from over 7,000 cryptocurrency wallets, transferring 1.7 billion Japanese yen, equivalent to 10.71 million USD, to North Korea. Primary targets included web designers, engineers, and specialists in blockchain and Web3 technologies.

Role of Laptop Farms

The advisory also details how North Korean IT workers generate foreign currency through “laptop farms,” locations, often an enabler’s residence, where employment computers are remotely controlled by workers based in North Korea, China, Russia, and occasionally Africa or Southeast Asia.

Enablers supply identification images, bank accounts, and internet connections, then forward payments to the workers after taking a cut. Japanese authorities dismantled a laptop farm for the first time domestically, uncovering evidence of several hundred million yen transferred abroad in cryptocurrency.

A related case involved a suspected North Korean applicant at a Japanese cryptocurrency exchange in May 2025, who submitted a forged resume, accessed the recruitment portal via VPN, and displayed mismatched language skills during a video interview. The company declined to hire the applicant, and no damage occurred.

The agencies list red flags including refusal of in-person meetings, requests for cryptocurrency payment, background voices during calls, and repeated video freezes.

Recommended defenses include avoiding execution of untrusted code outside a sandbox, treating VSCode projects with caution using “Restricted Mode,” deploying Endpoint Detection and Response tools, and immediately disconnecting compromised devices from the internet.

Victims are advised to assume wallet data has been exposed, create new wallets on separate devices, and perform full operating system resets.

International Cooperation Continues

The FBI stated it continues to prosecute US-based facilitators who assist North Korean IT workers, while Japanese and American authorities pledged ongoing cooperation to expose revenue-generation schemes benefiting the Kim regime. The advisory noted that WaterPlum and North Korean IT worker operations shared overlapping IP addresses across laptop farms, crowdsourcing platforms, and job applications, indicating coordinated infrastructure.

Companies and individual IT professionals are urged to review the tactics outlined in the advisory and strengthen hiring verification processes to prevent further infiltration.



Source link