North Korea’s notorious hacking group, known as WaterPlum or “Contagious Interview,” has been implicated in a significant cybersecurity breach that has affected at least 30,000 devices across more than 100 countries. Recent revelations from a joint advisory issued by various international law enforcement and cybersecurity agencies indicate that the group has compromised funds or credentials from over 7,000 cryptocurrency wallets. The alarming activities are believed to have taken place between December 2025 and July 2026, leading to an estimated transfer of at least JPY 1.7 billion (around $10.7 million) to North Korea.
The collaboration between Japan’s National Police Agency (NPA), Japan’s National Cybersecurity Office, the FBI, the Cyber Crime Center of the U.S. Defense Department, Australia’s Australian Cyber Security Centre (ACSC), and Germany’s Federal Intelligence Service (BND) alongside its domestic security agency (BfV) highlights the expansive reach of this cyber threat. These agencies have established a connection between WaterPlum and North Korean IT personnel operating under the 313 General Bureau, an entity that falls under the Munitions Industry Department of the Workers’ Party of Korea’s Central Committee.
### Ingenious Tactics: Fake Job Interviews
One of the more alarming techniques employed by WaterPlum involved masquerading as reputable employers, often impersonating firms engaged in artificial intelligence, cryptocurrency, or non-fungible tokens (NFTs). The group recruited unsuspecting developers through various platforms — including social media, job boards, and freelance marketplaces — with a particular focus on web designers, engineers, and specialists in cryptocurrency and Web3 technologies.
During what appeared to be technical interviews or coding assignments, victims were prompted to download and execute files hosted on developer platforms and code repositories. This deception allowed WaterPlum to deploy malicious packages, including those named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Notably, StoatWaffle is designed to infiltrate blockchain-themed Visual Studio Code (VSC) projects in such a way that it executes code automatically, posing a significant risk if the victim unknowingly trusts the folder.
Upon infiltration, WaterPlum operatives utilized remote access trojans alongside a suite of infostealers to capture various sensitive data, including browser credentials, keystrokes, screenshots, and private keys or seed phrases for cryptocurrency wallets and other identification documents. This level of access frequently allowed them to breach the systems of the victims’ employers as well.
### Overlapping Operations: WaterPlum and North Korean IT Workers
The advisory drew a compelling connection between WaterPlum’s operations and the North Korean IT worker scheme, noting that some individuals involved with WaterPlum concurrently function as official North Korean IT workers. Disturbingly, both groups leveraged the same IP addresses to access laptop farms and crowdsourcing services, and even made attempts to secure jobs at a cryptocurrency exchange in Japan.
Laptop farms—a concept defined as sites where remote-controlled computers for employment are set up—are often located in the homes of enablers who assist in the operation. These enablers supply identity documents, bank accounts, and virtual private servers to effectively disguise the actual locations of the North Korean workers involved.
In fact, Japanese authorities have recently made strides in combatting this issue, successfully identifying and dismantling a laptop farm for the first time in the country. Ongoing investigations have unveiled that North Korean IT personnel may have managed to move several hundred million yen outside Japan, including in cryptocurrency.
### Risks and Warnings for Businesses
Moreover, the threat posed by individuals who may turn destructive once hired cannot be overstated. Reports indicate that some North Korean workers have engaged in extortion practices, such as demanding payment from companies and subsequently publishing their source codes. Others have maliciously defaced client websites, rendering them inoperable.
To mitigate these risks, network agencies urge firms to take a comprehensive approach to security by implementing stricter controls over contractors’ access to critical source codes and credentials. Verification of applicants’ identities is also key, alongside careful scrutiny of any downstream subcontractors to avoid unintentionally falling victim to this insidious infiltration.
The context surrounding WaterPlum serves as a stark reminder of the need for vigilance in cybersecurity, particularly as sophisticated techniques evolve and the line between legitimate employment and cyber exploitation blurs.
