An unprecedented multinational security alert has detailed a sophisticated and far-reaching cyber espionage and financial illicit operation orchestrated by the North Korean state-sponsored group known as WaterPlum, revealing the compromise of over 30,000 devices across more than 100 countries and the illicit transfer of over $10.7 million in digital currencies to the Democratic People’s Republic of Korea (DPRK) over an eight-month period. This extensive campaign, active from December 2025 through July 2026, represents a significant escalation in Pyongyang’s efforts to circumvent international sanctions and fund its strategic weapons programs through illicit digital means. The findings, a result of collaborative investigations by leading intelligence and law enforcement agencies from Japan, the United States, Australia, and Germany, underscore the evolving threat landscape posed by state-backed cyber actors and the critical need for global vigilance.
The joint advisory paints a stark picture of WaterPlum’s capabilities and its systematic approach to financially motivated cybercrime. Operating under the umbrella of a multi-year campaign dubbed "Contagious Interview," the group has meticulously crafted an elaborate scheme targeting unsuspecting job seekers worldwide. By leveraging the universal desire for employment and professional advancement, WaterPlum employs highly deceptive social engineering tactics to gain initial access to target systems. This strategy has proven remarkably effective, leading to the infection of a vast network of personal and professional devices, ultimately serving as conduits for financial theft and potential intelligence gathering.
At the core of the "Contagious Interview" campaign is a sophisticated impersonation strategy. WaterPlum actors meticulously craft fake personas and digital infrastructures designed to mimic legitimate entities within high-growth sectors such as artificial intelligence (AI), cryptocurrency, and non-fungible token (NFT) markets. They also exploit popular recruiting platforms and freelance job boards, effectively casting a wide net to ensnare victims. Once a target is identified, typically an IT professional or a developer, the attackers initiate contact, often presenting attractive job opportunities that appear too good to pass up. The subsequent "interview" process is where the true deception unfolds.

During these fabricated interviews, which often include simulated coding tests or technical assessments, victims are instructed to download seemingly innocuous project files, troubleshoot staged video-conferencing issues, or execute specific code snippets as part of their evaluation. Unbeknownst to the applicants, these actions trigger the deployment of malicious software onto their devices. A particularly insidious aspect of this campaign involves the use of malicious npm packages. For developers, the npm (Node Package Manager) ecosystem is a ubiquitous repository for open-source code. By injecting malware into seemingly legitimate or cleverly disguised npm packages, WaterPlum exploits the trust inherent in software supply chains, allowing their malicious payloads to propagate widely and efficiently, often bypassing standard security checks. This method highlights a growing vulnerability in modern software development practices, where reliance on third-party libraries can introduce unforeseen risks.
The ramifications of a successful compromise are extensive. Once a device is infected, WaterPlum deploys a suite of tools designed for comprehensive data exfiltration and credential harvesting. The advisory explicitly links several malware families to WaterPlum’s operations, indicating a sophisticated and adaptable toolset. These tools are engineered to steal a wide array of sensitive information, including browser credentials, clipboard contents, keystrokes, and critically, cryptocurrency private keys and seed phrases. The theft of these digital assets allows the attackers direct access to victims’ cryptocurrency wallets, enabling the rapid transfer of funds. Beyond financial assets, the group also captures screenshots and exfiltrates documents, laying the groundwork for potential intellectual property theft and corporate espionage. The ability to pivot from an individual’s compromised device to their employer’s or client’s networks represents an even greater threat, transforming a personal financial crime into a potential national security incident or industrial espionage operation.
The financial scale of WaterPlum’s activities is staggering. The advisory confirms the exfiltration of funds or account credentials from over 7,000 cryptocurrency wallets, culminating in the transfer of 1.7 billion Japanese yen, equivalent to approximately $10.71 million USD, directly to the Democratic People’s Republic of Korea. This significant sum underscores the DPRK’s reliance on cybercrime as a primary mechanism for generating illicit revenue, circumventing stringent international sanctions imposed due to its nuclear and ballistic missile programs. This strategy of "digital financing" has become a cornerstone of the North Korean regime’s economic survival and its ability to fund its weapons development, posing a direct challenge to global non-proliferation efforts.
A particularly disturbing revelation from the joint investigation is the intricate link between the WaterPlum hacking operations and North Korea’s broader fraudulent IT worker schemes. The advisory states unequivocally that some WaterPlum hackers simultaneously operate as remote IT workers, offering web development and other technical services to unsuspecting clients worldwide. Investigators uncovered evidence of shared infrastructure, specifically the use of identical IP addresses, connecting these two seemingly disparate activities. This dual-pronged approach not only generates revenue through legitimate-looking work but also provides a cover for malicious activities and potentially aids in intelligence gathering. Furthermore, the advisory warns that identity documents stolen during WaterPlum attacks are subsequently repurposed by North Korean IT workers to impersonate victims and secure legitimate remote employment, thereby compounding the harm to individuals and further blurring the lines between cybercrime and espionage.

The deceptive tactics employed by these actors extend to the very human element of remote work. Investigators observed WaterPlum operatives utilizing advanced AI face-swapping software during initial online interviews, creating highly convincing but entirely fabricated personas. Following this initial visual deception, the attackers would then switch off their cameras, citing "network problems" or other technical glitches, thus maintaining their anonymity throughout subsequent interactions. This sophisticated blend of technological prowess and social engineering highlights the evolving challenges in verifying digital identities in an increasingly remote-first global economy.
Both the Federal Bureau of Investigation (FBI) and Japanese police authorities assess that WaterPlum actors and many of the fraudulent North Korean IT workers operate under the direct purview of the DPRK’s 313 General Bureau. This entity is understood to be a component of the Munitions Industry Department, a critical arm of the North Korean regime responsible for the nation’s weapons research and production. This direct organizational link provides undeniable evidence that these cyber activities are not merely opportunistic crimes but are state-sponsored operations explicitly designed to fuel Pyongyang’s strategic military objectives. The integration of cyber warfare capabilities with national defense infrastructure represents a severe and enduring threat to international security.
In a significant enforcement action, Japan’s National Police Agency successfully identified, investigated, and dismantled a North Korean IT-worker "laptop farm" within its borders. This groundbreaking operation marked the first time such an operational hub, facilitating illicit remote work and financial transfers, had been uncovered and disrupted in Japan. The investigation revealed evidence of several hundred million yen being transferred abroad, underscoring the tangible presence and operational reach of these networks even in highly regulated environments. This successful intervention serves as a critical precedent for international law enforcement in combating the physical infrastructure supporting state-sponsored cybercrime.
In light of these alarming revelations, the joint advisory issues urgent recommendations for both organizations and individuals to bolster their defenses. Companies are strongly advised to implement rigorous identity verification processes for all job applicants, particularly those seeking remote positions. This includes verifying their true location, qualifications, and employment history through multiple independent channels. Furthermore, organizations must strictly adhere to the principle of least privilege, restricting access for all employees, especially new hires or contractors, to only the systems and data absolutely necessary for them to perform their jobs. Enhanced security awareness training for all personnel, emphasizing the dangers of social engineering and sophisticated phishing attempts, is also paramount.

For developers and IT professionals, specific precautions are critical. It is imperative to avoid running unknown code outside of a secure sandbox environment. Before executing any code, especially that provided by external sources or during interview processes, developers must thoroughly inspect all provided files and code for commands that fetch additional payloads or exhibit suspicious behavior. Implementing robust software supply chain security measures, including rigorous vetting of third-party libraries and dependencies, is no longer optional but a fundamental requirement. Organizations should also deploy advanced endpoint detection and response (EDR) solutions and maintain comprehensive network segmentation to limit the potential for lateral movement in the event of a breach.
The WaterPlum campaign serves as a stark reminder of the persistent and evolving nature of state-sponsored cyber threats. The DPRK’s innovative and aggressive approach to generating illicit revenue through cybercrime, coupled with its willingness to exploit global vulnerabilities and human psychology, necessitates a continuous and coordinated international response. As technology advances and remote work becomes more prevalent, the sophistication of these attacks is only likely to increase, demanding unwavering vigilance, robust cybersecurity practices, and enhanced international collaboration to safeguard digital economies and global security. The ongoing cat-and-mouse game between state-sponsored hackers and global law enforcement will undoubtedly continue, emphasizing the critical need for proactive defense and intelligence sharing in this dynamic threat landscape.





