Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Victorian Labor promises new offences to close domestic and family violence ‘loopholes’ | Victorian politics

    September 19, 2026

    Germany’s top general to lead NATO’s highest military authority – POLITICO

    September 19, 2026

    AI safety conversations have gotten unbelievable

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Victorian Labor promises new offences to close domestic and family violence ‘loopholes’ | Victorian politics
    • Germany’s top general to lead NATO’s highest military authority – POLITICO
    • AI safety conversations have gotten unbelievable
    • TypeSafe AI Releases Jev: A System One Model That Returns Typed, Calibrated Decisions Instead of Text
    • Viral AI actress’ hotline face-scans every caller, watches their mood
    • The Next 3-5 Years Of Bitcoin Lending
    • Houthis claim attack on Riyadh after fire near airport
    • Even mid-sprint to a secret flight, the Navy’s tech chief has a pitch for investors
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    North Korean WaterPlum hackers infected 30,000 devices worldwide

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.

    The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group’s activity.

    WaterPlum is linked to a multi-year campaign known as “Contagious Interview,” which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.

    The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.

    During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

    Diagram
    Source: FBI

    WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.

    “WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,” reads the advisory.

    “WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).”

    The advisory links several malware families to WaterPlum operations, including:

    1. BeaverTail: JavaScript malware concealed in npm packages.
    2. InvisibleFerret: Python-based backdoor.
    3. OtterCookie: JavaScript remote-access trojan and information stealer.
    4. OtterCandy: Malware combining OtterCookie and RAT capabilities.
    5. StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.

    Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots.

    They may also use access to infected computers to pivot to their employers’ or clients’ networks, expanding the attacks to intellectual property theft and espionage.

    The agencies also directly connect WaterPlum to North Korea’s fraudulent IT worker operations, stating that some WaterPlum hackers also work as remote IT workers performing web development for clients and that the two groups have used the same IP addresses.

    The advisory also warns that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.

    Investigators also found that the WaterPlum actors use AI face-swapping software during online interviews, then turn off their cameras and blame network problems.

    FIB
    Source: FBI

    The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country’s 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea’s weapons research and production.

    Japan’s National Police Agency says authorities identified, investigated, and dismantled a North Korean IT-worker “laptop farm” in the country for the first time, finding evidence that several hundred million yen had been transferred abroad.

    The advisory warns companies to carefully verify job applicants’ identities, locations, and qualifications and restrict their access to only the systems and data required to perform their jobs.

    Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    devices hackers infected Korean North WaterPlum worldwide
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Viral AI actress’ hotline face-scans every caller, watches their mood

    BragJack attacks hijack AI browser agents through malicious extensions

    MIND Secures $72 Million for AI-Powered DLP

    TigerByte Cyber Emerges From Stealth With $3 Million in Funding

    ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

    Calling viral AI actress Tilly Norwood? Agree to a face scan first

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Victorian Labor promises new offences to close domestic and family violence ‘loopholes’ | Victorian politics

    September 19, 2026

    Germany’s top general to lead NATO’s highest military authority – POLITICO

    September 19, 2026

    AI safety conversations have gotten unbelievable

    September 19, 2026

    TypeSafe AI Releases Jev: A System One Model That Returns Typed, Calibrated Decisions Instead of Text

    September 19, 2026
    Latest Posts

    AIPAC Spending Dominates the Michigan Democratic Senate Primary

    August 5, 2026

    Labour members ‘have tougher view on welfare than you might think’, poll suggests | Labour

    August 5, 2026

    Palantir funnels earnings to US to avoid European taxes, report finds – POLITICO

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Victorian Labor promises new offences to close domestic and family violence ‘loopholes’ | Victorian politics

    September 19, 2026

    Germany’s top general to lead NATO’s highest military authority – POLITICO

    September 19, 2026

    AI safety conversations have gotten unbelievable

    September 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.