A joint advisory from Japanese, US, Australian, and German authorities says the North Korean hacking group WaterPlum compromised at least 30,000 devices in more than 100 countries between December 2025 and July 2026.
The authorities say WaterPlum transferred more than $10.7 million in stolen cryptocurrency to North Korea. Investigators traced more than 7,000 cryptocurrency wallets and identified transfers totaling 1.7 billion Japanese yen, equivalent to $10.71 million.
The group is linked to the multi-year Contagious Interview campaign, which targets job seekers through fake companies, recruiting platforms, and freelance services. Victims may be asked to download projects, troubleshoot supposed video-conferencing problems, or run code containing malware.
According to the advisory, WaterPlum malware can steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys, seed phrases, and documents, while also capturing screenshots. Attackers may use compromised systems to reach employers’ or clients’ networks.
The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country’s 313 General Bureau. Japanese authorities also said they dismantled a North Korean IT-worker “laptop farm” and found evidence that several hundred million yen had been transferred abroad. The advisory links the groups through shared IP addresses and warns that stolen identity documents may be reused to obtain jobs.
Comments
0No comments yet. Be the first to comment.