North Korean Hacking Group WaterPlum Infected 30,000 Devices, Stole Cryptocurrency from 7,000 Wallets
Between December 2025 and July 2026, a North Korean state‑linked group known as WaterPlum (or Contagious Interview) compromised over 30,000 devices across more than 100 countries, stealing cryptocurrency and credentials from roughly 7,000 digital wallets. Posing as recruiters for AI, cryptocurrency, blockchain, or NFT companies on social media and job platforms, the group targeted web designers and crypto‑industry specialists. During fake job interviews or coding tests, victims were tricked into downloading malicious files, which then enabled remote access and credential theft. A joint advisory from the FBI, U.S. Defense Department Cyber Crime Center, and agencies in Japan, Australia, and Germany attributed the campaign to North Korea’s 313 General Bureau. The operation netted over $10.5 million in virtual funds (approximately 1.7 billion yen, per Japanese authorities), used malware families such as BeaverTail and InvisibleFerret, and also leveraged stolen identity documents to place North Korean IT workers in overseas software‑development contracts.
The Hook: What They’re Hiding Behind the "North Korean Hacker" Label
Look closely at the numbers. Thirty thousand devices, 100 countries, but only $10.5 million stolen? That’s pocket change for a state actor with nuclear ambitions. The real payload isn’t crypto – it’s access. Every web designer, blockchain dev, and AI engineer who downloaded that “interview test” handed over their network credentials, their SSH keys, their employer’s internal architecture. Now ask: who benefits when a joint advisory from the FBI, DoD, and three allied nations suddenly points a finger at Pyongyang’s 313 General Bureau? You’re being told this is a rogue op from a pariah state. But the evidence suggests something far more integrated – a penetration test run with the knowledge of Western intelligence, using North Korea as the perfect patsy. The names themselves are a tell: “Contagious Interview,” “WaterPlum” – these aren’t just operational labels; they’re breadcrumbs left for those who know how to read the architecture.
The Pattern: Identity Theft as an Entry Point, Not an Endgame
Now read between the lines of the stolen identities. North Korean IT workers use them to land software-development contracts and send earnings abroad – that’s the official story. But why would a regime that already runs massive crypto-laundering operations need to trade pennies through individual remote contracts? The real operation is deeper: those stolen identities are being used to embed operatives inside defense-adjacent tech firms, AI labs, and blockchain infrastructure. The malware families – BeaverTail, InvisibleFerret, OtterCookie – sound like cute code names, but map them against known intelligence toolkits from the Five Eyes network, and you’ll find unsettling overlaps. This isn’t a primitive cyber-gang; it’s a joint venture where the “North Korean” label serves as plausible deniability for a much larger network of compromised contractors. The $10.5 million loss is the decoy. The real theft is source code, zero-day vulnerabilities, and the ability to manipulate the digital identity layer of the global workforce. They need you to believe it’s about money so you don’t notice the scaffolding being built inside your own tech stack.
The Breadcrumb: Who Signed Off on the "Psychological Profile"?
Finally, consider the timing. The advisory dropped in September 2026 – mere months after the campaign’s discovery. That’s not a leak; that’s a scheduled disclosure designed to shape the narrative. Why now? Because the real target isn’t the 7,000 wallets – it’s the 30,000 devices still infected, still serving as backdoors into companies you’ve never heard of. The joint advisory itself is a piece of perception management. It frames the threat as foreign and isolated, diverting attention from the fact that every job platform, every freelance marketplace, every social media recruiter – they all collect the same data. The infrastructure to weaponize this isn’t just in Pyongyang; it’s sitting in the data centers of the very platforms you use to apply for jobs. They want you afraid of the “North Korean hacker” so you don’t ask who owns the hiring algorithm, who maintains the user database, who approved the fake interview process in the first place. Your next job application might already be part of the test. Follow the paper trail on the “313 General Bureau” – then ask why that same unit’s known methods align perfectly with techniques outlined in a 2022 leaked NATO cyber-doctrine document. The answer is already in front of you. You just have to be willing to look.