An unprecedented multi-national law enforcement investigation has uncovered a massive, sophisticated cyberespionage and financial theft operation orchestrated by the North Korean state-sponsored threat group known as WaterPlum. According to a joint cybersecurity advisory issued by authorities in the United States, Japan, Australia, and Germany, the threat actors successfully compromised a minimum of 30,000 individual devices across more than 100 countries between December 2025 and July 2026. The coordinated offensive resulted in the illicit laundering of over $10.7 million in stolen cryptocurrency directly back to the Democratic People’s Republic of Korea (DPRK), serving to financially back the regime’s illicit weapons development programs.
The comprehensive joint report highlights the evolving tactics of state-backed hacking syndicates that target global IT professionals, software developers, and cryptocurrency investors. By blending advanced social engineering, AI-driven deception, and malicious software packaging, WaterPlum has established a pervasive threat infrastructure that weaponizes the recruitment processes of Western and allied technological firms.
Anatomy of the Campaign: The "Contagious Interview" Trap
At the core of WaterPlum’s operational success is the multi-year "Contagious Interview" campaign. This sophisticated social engineering scheme heavily targets job seekers in the information technology and cryptocurrency sectors. The threat actors routinely pose as legitimate recruiters, human resources representatives, or executives from prominent artificial intelligence, cryptocurrency, and NFT enterprises. They utilize popular freelance marketplaces, professional networking sites, and specialized job boards to approach prospective targets with lucrative employment offers.
Once engagement is established, the victims are invited to participate in remote technical screenings, coding tests, or interviews. During these interactions, the attackers employ various ruses to compromise the victim’s hardware. Candidates are frequently instructed to clone and run specific open-source software projects, troubleshoot fabricated video-conferencing connection errors, or execute ostensibly harmless scripts required for the evaluation process.
In many instances, the campaign has leveraged malicious packages distributed via public code repositories, such as compromised npm packages, which silently deploy information-stealing malware the moment they are compiled or executed on a developer’s machine. Once inside the local environment, the malware aggressively harvests sensitive data. Investigators noted that the software is engineered to capture browser-stored credentials, clipboard contents, active keystrokes, personal documents, and screen captures. Crucially, the payload targets cryptocurrency infrastructure by extracting private keys and seed phrases from digital wallets. According to the international advisory, the group successfully compromised account credentials or exfiltrated funds from upwards of 7,000 individual cryptocurrency wallets worldwide.

Chronology and Scale of the Threat
The timeline outlined by the coalition details a concentrated surge in operational activity stretching from the winter of 2025 through the summer of 2026. However, security researchers note that the foundations of the campaign extend years prior through iterative testing of supply-chain vector attacks.
By December 2025, intelligence agencies observed a dramatic uptick in anomalous cryptocurrency transactions linked to wallets controlled by the DPRK. Concurrently, software supply-chain monitors flagged an unprecedented influx of malicious packages designed to target software developers. Over the subsequent eight months, the coalition tracked the expansion of the botnet, culminating in the milestone of 30,000 infected devices by July 2026.
Financial tracing conducted by the coalition indicates that the threat actors successfully converted and transferred 1.7 billion Japanese yen—equivalent to approximately $10.71 million USD—into the DPRK. This capital injection directly supports state objectives, specifically feeding the financial reservoirs of the regime’s military research units.
Nexus with Fraudulent IT Worker Operations and AI Spoofing
One of the most revealing findings within the joint advisory is the direct operational overlap between WaterPlum hackers and North Korea’s sprawling network of fraudulent overseas IT workers. Intelligence agencies discovered that individuals operating within the WaterPlum hacking collective frequently double as remote contract web developers for international clients. In several instances, forensic analysts identified shared infrastructure and identical Internet Protocol (IP) addresses utilized by both the cyberespionage hackers and the fraudulent IT workers.
Furthermore, the advisory highlights a grim cycle of identity theft. North Korean IT workers routinely utilize stolen identity documents—harvested directly through WaterPlum intrusions—to pass digital KYC (Know Your Customer) checks, complete background verifications, and secure high-paying remote employment with Western companies. Once hired, these operatives funnel a significant portion of their salaries back to Pyongyang, while simultaneously using their internal network access to conduct corporate espionage and intellectual property theft.

To circumvent security measures during the hiring phase, WaterPlum operatives have increasingly adopted artificial intelligence-powered face-swapping software. During live video interviews, these actors deploy real-time digital avatars to mask their true appearance. When pressed or when technical glitches are simulated, the hackers deliberately disable their webcams, attributing the video feed failure to transient network instabilities.
Attribution to the 313 General Bureau and the "Laptop Farm" Bust
Law enforcement and intelligence assessments place the command and control of WaterPlum and its associated IT worker rings squarely under the jurisdiction of North Korea’s 313 General Bureau. This bureau operates as a subordinate entity within the Munitions Industry Department, the governmental body explicitly tasked with overseeing the research, development, and production of the nation’s ballistic missiles and nuclear weapons arsenal.
In a landmark domestic enforcement action, Japan’s National Police Agency announced that authorities had successfully identified, investigated, and physically dismantled a North Korean IT-worker "laptop farm" operating within the country. This marked the first time Japanese law enforcement dismantled such an infrastructure node on domestic soil. Investigators recovered substantial evidence indicating that several hundred million yen had been illicitly transferred overseas via the facility, which utilized proxy hardware to deceive foreign employers regarding the true geographic location of the workers.
Implications for Corporate Security and the Global Software Supply Chain
The revelations detailed in the joint advisory underscore a profound structural vulnerability in the modern remote-work economy. The globalization of the IT workforce, accelerated by post-pandemic remote work trends, has inadvertently provided state-sponsored threat actors with a frictionless entry point into critical corporate networks.
By infiltrating a single developer’s workstation, actors can easily pivot from personal environments into corporate networks, gaining unfettered access to proprietary source code, internal staging environments, and sensitive customer data. This creates a dual-threat vector: immediate financial extortion through ransomware and cryptocurrency theft, paired with long-term strategic espionage and intellectual property pillaging.

Security analysts emphasize that traditional perimeter defenses are entirely inadequate against attacks initiated by trusted, authenticated remote employees whose credentials have been validated through fraudulent or stolen identities. The ability of hostile nation-states to weaponize the standard hiring pipeline turns a company’s own human resources and recruitment apparatuses into unwitting vectors for national security breaches.
Defensive Recommendations and Industry Guidance
In response to the escalating threat posed by WaterPlum and aligned DPRK cells, the issuing authorities—including the FBI, the Australian Cyber Security Centre (ACSC), the German Federal Office for the Protection of the Constitution (BfV), and Japan’s National Police Agency—have issued a comprehensive series of mitigation recommendations for organizations and individual developers alike.
For corporate entities and human resources departments, the agencies advise rigorous validation of applicant identities. Companies must move beyond basic video interviews by requiring robust multi-factor identity verification, conducting live reference checks, and cross-referencing employment histories with primary sources. Furthermore, organizations are strongly urged to enforce the principle of least privilege, restricting remote contractors and third-party developers to only the specific data repositories and infrastructure environments strictly required for their assigned tasks. Continuous behavioral monitoring of endpoints can help detect anomalous data exfiltration or unauthorized script executions in real-time.
For software developers and technical personnel, the advisory stresses strict hygiene regarding open-source dependencies. Developers should never execute unverified code, scripts, or binaries outside of a securely isolated sandbox environment. Codebases and dependency manifests should be carefully inspected for obfuscated commands, unexpected network callbacks, or unauthorized routines designed to fetch external payloads from remote servers.
As state-sponsored threat groups continue to refine their methodologies, integrating advanced AI capabilities and sophisticated social engineering, the international cybersecurity community emphasizes that organizational vigilance remains the primary bulwark against financially and politically motivated cyber campaigns.
