North Korea’s WaterPlum Group Steals $10.7M in Crypto via Fake Job Scams
A joint advisory by Japan’s National Police Agency (NPA), the FBI, Australia’s ACSC, Germany’s BND and BfV, and the U.S. Defense Department’s Cyber Crime Center reveals that North Korea’s WaterPlum (aka Contagious Interview) hacking group compromised 30,000 devices across 100+ countries between December 2025 and July 2026, siphoning funds from 7,000+ cryptocurrency wallets and funneling $10.7 million (JPY 1.7 billion) to Pyongyang.
The group, linked to North Korea’s 313 General Bureau under the Munitions Industry Department, targeted web designers, engineers, and Web3/cryptocurrency specialists through fake job interviews. Posing as employers from AI, crypto, or NFT firms, WaterPlum actors recruited victims via social media, job boards, and freelance platforms, tricking them into downloading malicious NPM packages (e.g., BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffel) during technical assessments.
StoatWaffel, a key malware strain, was embedded in blockchain-themed Visual Studio Code projects, executing automatically when victims opened the files. Once infected, devices were hijacked with remote access trojans and infostealers, harvesting browser credentials, keystrokes, wallet private keys, seed phrases, and ID documents. The attacks also provided a foothold into victims’ employers.
The advisory highlights overlap between WaterPlum and North Korea’s IT worker scheme, with some hackers doubling as fraudulent freelancers. Both groups used the same IP addresses to access laptop farms remote setups where North Korean operatives control employment devices using stolen identities and virtual private servers. Japanese authorities dismantled a laptop farm for the first time, uncovering evidence of hundreds of millions of yen moved abroad, including crypto.
Some North Korean IT workers turned destructive after hiring, with incidents including extortion, source code leaks, and website defacements. The advisory notes that one worker published a company’s proprietary code after a payment dispute, while another took a client’s site offline.
Source: https://www.infosecurity-magazine.com/news/north-korean-waterplum-30000/
313SEC cybersecurity rating report: https://www.rankiteo.com/company/313sec
"id": "3131790087037",
"linkid": "313sec",
"type": "Cyber Attack",
"date": "12/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '7,000+ cryptocurrency wallets',
'industry': ['Web Design',
'Engineering',
'Cryptocurrency',
'AI',
'NFT'],
'location': '100+ countries',
'type': ['Individuals',
'Cryptocurrency users',
'Web3/crypto firms']}],
'attack_vector': ['Fake job interviews',
'Malicious NPM packages',
'Social media/job boards'],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes (ID documents)',
'sensitivity_of_data': 'High (PII, financial, and '
'cryptocurrency-related data)',
'type_of_data_compromised': ['Browser credentials',
'Keystrokes',
'Wallet private keys',
'Seed phrases',
'ID documents']},
'description': 'North Korea’s WaterPlum (aka Contagious Interview) hacking '
'group compromised 30,000 devices across 100+ countries '
'between December 2025 and July 2026, siphoning funds from '
'7,000+ cryptocurrency wallets and funneling $10.7 million '
'(JPY 1.7 billion) to Pyongyang. The group targeted web '
'designers, engineers, and Web3/cryptocurrency specialists '
'through fake job interviews, tricking them into downloading '
'malicious NPM packages during technical assessments.',
'impact': {'data_compromised': ['Browser credentials',
'Keystrokes',
'Wallet private keys',
'Seed phrases',
'ID documents'],
'financial_loss': '$10.7 million (JPY 1.7 billion)',
'identity_theft_risk': 'High (ID documents and PII compromised)',
'operational_impact': ['Remote access trojan infections',
'Infostealer deployments',
'Foothold into victims’ employers'],
'payment_information_risk': 'High (cryptocurrency wallet private '
'keys and seed phrases compromised)',
'systems_affected': '30,000 devices across 100+ countries'},
'initial_access_broker': {'backdoors_established': 'Remote access trojans and '
'infostealers',
'entry_point': ['Fake job interviews',
'Malicious NPM packages'],
'high_value_targets': ['Web designers',
'Engineers',
'Web3/cryptocurrency '
'specialists']},
'investigation_status': 'Ongoing',
'motivation': ['Financial gain', 'State-sponsored cyber espionage'],
'post_incident_analysis': {'root_causes': ['Social engineering (fake job '
'interviews)',
'Malicious NPM packages',
'Lack of security awareness among '
'victims']},
'references': [{'source': 'Joint advisory by Japan’s NPA, FBI, ACSC, '
'Germany’s BND and BfV, and U.S. Defense '
'Department’s Cyber Crime Center'}],
'response': {'law_enforcement_notified': 'Japan’s NPA, FBI, ACSC, Germany’s '
'BND and BfV, U.S. Defense '
'Department’s Cyber Crime Center'},
'threat_actor': 'WaterPlum (aka Contagious Interview), linked to North '
'Korea’s 313 General Bureau under the Munitions Industry '
'Department',
'title': 'North Korea’s WaterPlum Group Steals $10.7M in Crypto via Fake Job '
'Scams',
'type': 'Cybercrime, Cryptocurrency Theft, Social Engineering',
'vulnerability_exploited': 'Malicious NPM packages (e.g., BeaverTail, '
'InvisibleFerret, OtterCookie, OtterCandy, '
'StoatWaffel)'}