North Korean WaterPlum hackers infected 30,000 devices
A North Korean hacking group known as WaterPlum compromised at least 30,000 devices globally between December 2025 and July 2026. The operation siphoned over $10.7 million in cryptocurrency, with the funds funneled directly back to North Korea.

The figures come from a joint advisory issued by Japanese, US, Australian, and German authorities, who tracked the group’s activities across more than 100 countries. WaterPlum is part of a broader network of North Korean actors running financially motivated attacks to fund the regime’s weapons programs.

Fake Interviews as an Attack Vector

WaterPlum is linked to a multi-year campaign called Contagious Interview, which specifically targets job seekers with malicious npm packages. The packages infect devices with malware during fake interviews and coding tests, turning the hiring process itself into the delivery mechanism.

Attackers impersonate legitimate AI, cryptocurrency, and NFT companies, then approach victims through recruiting and freelance platforms. During these fake interactions, victims are instructed to download projects or execute code as part of a supposed technical assessment. There’s no interview happening. There’s only an infection waiting for a click.

The Malware Behind the Campaign

The advisory names several malware families tied to WaterPlum operations:

  • BeaverTail, JavaScript malware hidden inside npm packages
  • InvisibleFerret, a Python-based backdoor
  • OtterCookie, a JavaScript remote-access trojan
  • OtterCandy, which combines OtterCookie with additional RAT capabilities
  • StoatWaffle, a modular Node.js malware delivered through malicious Visual Studio Code projects

Once a target is compromised, attackers steal credentials, clipboard contents, keystrokes, and cryptocurrency private keys. They also capture screenshots and can pivot into employers’ or clients’ networks for intellectual property theft and espionage.

When the Hackers Are Also the Employees

Investigators found a direct link between WaterPlum and North Korea’s fraudulent IT worker operations. Some WaterPlum hackers also work remotely as legitimate IT professionals, performing real web development for real clients, often using stolen identity documents from prior WaterPlum attacks to land the jobs in the first place.

During interviews, these operatives use AI face-swapping software, then conveniently turn off their cameras and blame network issues once hired. The same identity theft pipeline funds both the espionage and the disguise.

Traced to a State Weapons Bureau

The FBI and Japanese police assess that WaterPlum actors and North Korean IT workers operate under the country’s 313 General Bureau, part of the Munitions Industry Department responsible for North Korea’s weapons research and production. This isn’t freelance cybercrime. It’s state infrastructure.

Japan’s National Police Agency identified and dismantled a North Korean IT worker laptop farm operating inside the country, uncovering evidence of several hundred million yen transferred abroad through the scheme.

What Companies Are Being Told to Do

The joint advisory urges companies to rigorously verify job applicants’ identities, locations, and qualifications, and to restrict new hires’ access to only essential systems and data during onboarding.

Developers are advised to avoid running unknown code outside a sandbox and to inspect any provided files or code for commands that fetch additional payloads before execution.

Hashlytics Take

The 30,000 figure is the headline, but the actual vulnerability being exploited is trust in the hiring process itself. Most companies have security reviews for production code and vendor access, but almost none have a security review for a candidate’s take-home coding test. WaterPlum figured out that the interview pipeline was an unguarded door, and they’ve been walking through it since long before this advisory named them. Until hiring workflows treat unverified code from applicants the same way they’d treat an unsolicited attachment, this specific attack surface isn’t closing anytime soon.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates