North Korean WaterPlum hackers infected 30,000 devices worldwide

North Korean Hackers Compromise 30,000 Devices Globally, Steal Millions in Cryptocurrency

A joint law enforcement advisory has revealed that a group of North Korean hackers known as WaterPlum has infected at least 30,000 devices worldwide over the past eight months. The hackers have been linked to a broader campaign called “Contagious Interview,” which targets job seekers with malicious software disguised as legitimate AI and cryptocurrency projects.

The victims are approached by the attackers through fake interviews and coding tests, where they are instructed to download suspicious code or execute malware-laced instructions. This is just one tactic used by WaterPlum, a group linked to North Korea’s 313 General Bureau, which is responsible for the country’s weapons research and production. The bureau generates revenue for the regime by conducting financially motivated attacks.

The advisory, issued jointly by Japanese, US, Australian, and German authorities, details the scope of the operation. WaterPlum actors have transferred over $10 million in cryptocurrency to North Korea, compromising more than 7,000 wallets worldwide. The hackers used a range of malware families to carry out their attacks, including JavaScript-based backdoors and information stealers.

One of the most concerning aspects of this campaign is how it leverages job seekers’ trust. WaterPlum actors impersonate legitimate companies or use recruiting platforms to approach victims. They then use AI face-swapping software during online interviews before turning off their cameras and blaming network problems. This tactic allows them to gather sensitive information without arousing suspicion.

The advisory also highlights the intersection of WaterPlum’s activities with North Korea’s IT worker operations. Some hackers work as remote IT workers, performing web development for clients while also carrying out malicious activities on behalf of the regime. The agencies warn that these actors reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.

To mitigate this threat, companies are advised to carefully verify job applicants’ identities, locations, and qualifications before granting them access to sensitive systems and data. Developers should exercise caution when running unknown code outside a sandbox and inspect provided files for malicious commands that fetch additional payloads.

The joint advisory serves as a stark reminder of the ongoing threats posed by nation-state actors in the cybersecurity landscape. As organizations continue to adopt new technologies, including AI-powered tools, they must remain vigilant against the evolving tactics employed by these groups.


Source: Bleeping Computer — 2026-09-19