Skip to content
Tech News
← Back to articles

North Korean WaterPlum hackers infected 30,000 devices worldwide

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

This advisory highlights the growing scale and sophistication of North Korean state-sponsored cybercrime, which increasingly uses fake job interviews and malicious coding assignments to infect developers and crypto professionals. The campaign's success in stealing over $10 million shows how effectively these tactics evade traditional security awareness, posing risks to any company hiring remote tech talent or handling cryptocurrency.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — With North Korean hackers like WaterPlum targeting job seekers through fake interviews and malicious downloads, hardware-based two-factor authentication is a smart layer of defense for crypto wallets, email, and developer accounts. A YubiKey helps ensure that even if malware steals your passwords, attackers can't log into your critical accounts without the physical key in hand.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.

The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group's activity.

WaterPlum is linked to a multi-year campaign known as "Contagious Interview," which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.

The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.

During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

Source: FBI

WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.

"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets," reads the advisory.

"WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK)."

The advisory links several malware families to WaterPlum operations, including:

... continue reading