Advertisement

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs.

Hack Database

WaterPlum: North Korea's Fake Recruiters Infected 30,000 Computers and Sent $10.7M Home

Seven agencies in four countries say North Korean fake recruiters infected 30,000 job seekers' computers and sent $10.7M in stolen crypto home.

WaterPlum: North Korea's Fake Recruiters Infected 30,000 Computers and Sent $10.7M HomeLogos: FBI, National Police Agency, BND, BfV (public domain, via Wikimedia Commons); ASD (via Wikipedia)
Five of the seven agencies that named WaterPlum: the FBI, Japan's National Police Agency, Australia's ASD, and Germany's BND and BfV.

Key numbers

  • $10.7M

    Stolen

  • 30,000+

    Devices infected

  • 7,000+

    Wallets hit

  • North Korea (WaterPlum)

    Attacker

The job offer looks ordinary. A recruiter for an artificial intelligence start-up, a crypto firm or an NFT marketplace finds a software developer on a freelance site and suggests a video interview. On the call the recruiter's face looks normal, because software is generating it live. A few minutes in, the recruiter's camera goes off. The network is bad, the candidate is told, so it would be better to switch off both cameras. Then comes a coding test, or a file that will supposedly fix the video call. The candidate downloads it and runs it. From that moment, according to four governments, the computer is working for North Korea.

On 18 September 2026, seven agencies from Japan, the United States, Australia and Germany published a joint advisory naming the people behind those calls. They call the group WaterPlum. Between about December 2025 and July 2026, the advisory says, WaterPlum infected at least 30,000 computers in more than 100 countries, took money or login details from more than 7,000 crypto wallets, and sent 1.7 billion yen of cryptocurrency, about $10.71 million, to North Korea.

By North Korean standards the money is small. Six days after the advisory, the exchange Bitget lost $387.5 million in one evening to hackers it believes were North Korean. The reach is what stands out: 30,000 people whose passwords, identity documents and often employers' systems were open to the same operators.

Bar chart: WaterPlum $10.7M, Bitget $388M (suspected), Bybit $1.5B, North Korea total for 2025 $2.02BCMZ chart. Data: joint advisory, Bitget, FBI, Chainalysis
WaterPlum's take beside North Korea's biggest thefts.
Advertisement

Free AI assistant

AI that works, and proves it.

Ask Cynt how AI could help your business. Free to try.

Free AI assistant

Who signed it and what they said

The advisory carries seven names: the National Police Agency of Japan and Japan's National Cybersecurity Office; the Federal Bureau of Investigation and the Department of Defense Cyber Crime Center in the United States; the Australian Signals Directorate's Australian Cyber Security Centre; and Germany's Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV). Its opening summary is blunt: "WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities."

The National Police Agency and the FBI go further on who gives the orders. They assess that WaterPlum, and some of the North Korean IT workers who take remote jobs at foreign companies under false names, "operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea". In plain terms, the hackers and the fake employees answer to the ruling party's weapons-industry department. The Japanese police release called the activity a threat to security and economic activity "not only for Japan but for the world". No one has been charged over WaterPlum, and the attribution is the governments' assessment.

Researchers have tracked the operation for years under another name. Palo Alto Networks' Unit 42 called it Contagious Interview in November 2023, when it first described North Korean "employers" handing developers poisoned coding tests.

How the fake interview works

The approach comes through social media, job sites, gig platforms and freelance marketplaces. WaterPlum poses as real AI, crypto and NFT companies, and sometimes uses genuine recruiting services. Interviews run online. The advisory records that members "conducted online interviews using AI face-swapping software" and that after a few minutes they "disabled their video and advised the target to disable their video due to network issues".

The trap is the homework. Candidates are told to download a project from a code-sharing site such as GitHub or Bitbucket and run it, either to complete a coding assignment or to "troubleshoot an error" in the video-call software. Modern programs are assembled from ready-made building blocks called npm packages, much as a builder orders standard parts from a catalogue. WaterPlum uploads poisoned parts. They carry malware, software that secretly does something its owner never asked for, in five named families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. StoatWaffle hides in blockchain-themed projects for Visual Studio Code, a popular code editor, and starts itself the moment a developer opens the folder and clicks to trust it. In November 2024 Unit 42 found a variation: fake installers for the video-call services MiroTalk and FreeConference.

Once running, the malware installs a hidden remote control, known as a remote-access trojan, and an information stealer. The advisory lists the haul: passwords saved in web browsers, anything copied to the clipboard, every keystroke, screenshots, photos of driving licences and passports, and crypto wallet data including private keys and seed phrases.

The seed phrase is the prize. It is a list of 12 or 24 ordinary words that works as the master key to a crypto wallet. Anyone holding it can rebuild the wallet on another device and move the money, and there is no bank to ring and no transfer to reverse. It behaves like a bearer bond: whoever holds the paper owns the money.

Why developers make good targets

Developers run other people's code for a living, so a test that means running a stranger's project looks normal. The primary targets, the advisory says, were web designers, engineers and specialists in cryptocurrency, blockchain and Web3, people likely to hold crypto themselves. Their laptops also open doors to employers' systems, which the agencies say allows espionage and theft of trade secrets. Stolen ID photos are recycled: North Korean IT workers use them to pose as the victims and win paid work.

That is the link the advisory draws between the hackers and the fake employees. For the first time in Japan, police identified and shut down a "laptop farm", a home where a local helper keeps company laptops switched on so that workers abroad can control them remotely and appear to be in the country. The workers behind it moved several hundred million yen abroad. The same internet addresses showed up at the laptop farm, on freelance platforms and in a job application. In May 2025 a candidate applied for an engineering post at a Japanese crypto exchange, which Japanese outlets identified as bitFlyer. He claimed to be a Malaysian living in Finland, could not discuss most of the skills on his CV, and was not hired.

The advisory also records habits. WaterPlum members practised Japanese with text-to-speech software, used free AI plans, and on North Korean holidays watched football instead of working.

How to spot a fake interview

A recruiter whose camera fails after a few minutes, an interview that turns into instructions to download and run something, and a video-call "fix" that arrives as a file are all warning signs. Developers are told never to run code from strangers on a computer that holds crypto or personal data, and to test unknown projects only in a sandbox or virtual machine, a sealed-off practice computer that can be thrown away. Commands containing words such as "curl", "base64", "-enc", "mshta" or "hidden" deserve suspicion. In Visual Studio Code, answering "No" when asked whether to trust the folder's author opens it in Restricted Mode, which stops the auto-run trick.

Anyone who suspects infection should disconnect the machine from the internet and assume the wallet is already stolen. The agencies say to create a new wallet on a separate, clean device, move everything into it, write the new seed phrase down offline, then wipe and reinstall the old computer. Employers get their own list: candidates who refuse to meet in person, want paying in crypto, keep glancing at another screen or have voices in the background. The agencies suggest checking that an applicant's internet address matches where they claim to live, ringing the phone number on the CV, and asking about hometowns, local weather and hobbies.

The bigger North Korea picture

WaterPlum is the retail end of a state business. Chainalysis estimated North Korean hackers stole $2.02 billion in crypto in 2025, most of it the $1.5 billion taken from Bybit, which the FBI attributed to TraderTraitor, part of the operation widely known as the Lazarus Group. The $625 million Ronin Bridge theft in 2022 began, according to later reporting, with a fake job offer sent to an engineer at Sky Mavis. In July 2026 Consensys, the company behind the MetaMask wallet, found that a North Korea-linked contractor had spent about a month writing its code. Elliptic says the Bitget theft pushes North Korea's suspected 2026 haul past $1 billion, though no government has formally attributed it.

Andrew Cullen of the University of Melbourne told ABC News he had "seen reports of fake North Korean employees for the last three to four years but it has been accelerating".

The aftermath

As of 1 October 2026 no one has been charged over WaterPlum and none of the $10.71 million is reported to have been recovered. The attribution to North Korea's 313 General Bureau rests on the assessment of the National Police Agency of Japan and the FBI, supported by matching internet addresses across the hacking, the laptop farm and the fake job application.

Japan's first known North Korean laptop farm has been dismantled, and the FBI says it continues to prosecute people in the United States who help North Korean IT workers get and keep jobs. The advisory warns that paying North Korean IT workers, even unknowingly through subcontractors, may breach Japanese law and sanctions against North Korea, and asks companies to report suspected workers to police.

The group is not expected to stop. The agencies describe their list of tricks as "only examples" and say the actors continuously refine their methods. The advisory came six days before the $387.5 million Bitget theft, which analysts have linked to North Korea's separate TraderTraitor operation.

What this teaches

  • A job interview that ends with an instruction to download and run something is the attack. Real employers can test skills without running unknown code on a personal computer.
  • A recruiter's camera that fails after a few minutes is a listed warning sign: WaterPlum used AI face-swapping and then switched video off, blaming the network.
  • Unknown code belongs in a sandbox or virtual machine, never on a computer that holds a crypto wallet, saved passwords or ID documents.
  • After any suspected infection, treat the seed phrase as stolen: make a new wallet on a clean device and move everything, rather than just deleting the malware.
  • Employers face the mirror image: North Korean IT workers apply with stolen identities, avoid meeting in person, ask for crypto pay and route through laptop farms.
Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI