North Korean Hackers Infiltrate 30,000 Devices Worldwide, Steal Over $10 Million in Cryptocurrency
A devastating cybersecurity attack perpetrated by North Korea’s WaterPlum hacking group has compromised at least 30,000 devices globally, with the group transferring over $10.7 million in stolen cryptocurrency to their home country. The alarming figure comes from a joint advisory issued by authorities from Japan, the US, Australia, and Germany, who have collectively tracked the threat group’s activity.
WaterPlum is part of a larger campaign known as “Contagious Interview,” which has been targeting job seekers with malicious npm packages that infect their devices with malware. The attackers pose as legitimate AI, cryptocurrency, and NFT companies or use recruiting platforms to approach potential victims. During fake interviews and coding tests, the hackers instruct victims to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.
The advisory warns that WaterPlum actors have infected at least 30,000 devices in over 100 countries, exfiltrating funds or account credentials from more than 7,000 cryptocurrency wallets. The group has transferred an astonishing 1.7 billion Japanese yen (equivalent to $10.71 million USD) of cryptocurrency assets to North Korea.
The joint advisory links several malware families to WaterPlum operations, including JavaScript-based backdoors, Python-based backdoors, and remote-access trojans. Once a target is compromised, the attackers attempt to steal sensitive information such as browser credentials, clipboard contents, keystrokes, and cryptocurrency private keys. They may also use access to infected computers to pivot to their employers’ or clients’ networks, expanding the attacks to intellectual property theft and espionage.
The agencies directly connect WaterPlum to North Korea’s fraudulent IT worker operations, stating that some hackers work as remote IT workers performing web development for clients while using the same IP addresses. The advisory also warns that North Korean IT workers reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.
To mitigate this threat, companies are advised to carefully verify job applicants’ identities, locations, and qualifications, restricting their access to only the systems and data required to perform their jobs. Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.
The WaterPlum attack highlights the importance of vigilance in today’s cybersecurity landscape. With attackers increasingly using sophisticated tactics like AI face-swapping software during online interviews, it is essential to stay informed about emerging threats and adapt security measures accordingly. By taking proactive steps to protect against these types of attacks, individuals and organizations can reduce their risk of falling victim to the WaterPlum hacking group.
Source: Bleeping Computer — 2026-09-19