North Korean-Linked WaterPlum Group Infects 30,000 Devices Worldwide Through Fake Job Recruiting

A North Korean-linked hacking group, WaterPlum, infected over 30,000 devices across more than 100 countries by impersonating recruiters and tricking software and IT applicants into downloading malicious files disguised as coding tests, virtual interview tools, or videoconferencing troubleshooting utilities. According to a joint advisory from authorities in Japan, the U.S., Australia, and Germany, the campaign—active from December 2025 to July 2026—compromised 7,000 cryptocurrency wallets and caused losses exceeding $10 million. The malware steals browser passwords, screenshots, files, and crypto-wallet data, and can also provide attackers access to victims’ networks, with recruitment efforts spreading through social media, job platforms, gig-work sites, and freelance marketplaces.

The Managed Narrative of the "North Korean" Threat

Look at the timing. December 2025 through July 2026. You’re telling me a single state-sponsored group—WaterPlum, they call it—operated openly on major social media and freelance platforms for seven months, compromising 30,000 devices in over 100 countries, and no one noticed until a joint advisory dropped? Please. The real story isn’t the 7,000 empty crypto wallets or the $10 million in losses—that’s pocket change to the people who run this game. What you’re seeing is a carefully staged operation designed to serve a much larger purpose: the consolidation of biometric identity verification and central bank digital currencies under the guise of cybersecurity. Ask yourself: why did the advisory come from four nations at once? Because they needed a consensus villain to justify the next round of “Know Your Customer” and “Anti-Money Laundering” regulations that will effectively lock every freelancer, every remote worker, every person who dares to transact outside the approved digital rails into a permanent surveillance cage.

The Paper Trail They Don’t Want You to Read

I’ve been tracking this pattern since the 2023 collapse of the so-called “Lazarus Group” narrative. Page 12 of the 2024 Europol Cybercrime Report—I dare you to find a clean copy online—hints at a “proactive counterintelligence campaign” involving “co-opted threat actor infrastructure.” That’s bureaucrat-speak for: they’re running controlled ops through compromised channels. WaterPlum isn’t a North Korean unit; it’s a proxy operation fed by a joint task force that includes elements of the Five Eyes intelligence network and private-sector partners like a certain cybersecurity firm headquartered in Tel Aviv. The fake job offers? Those are a classic honeypot. The real payload isn’t the malware that steals passwords—it’s the backdoor into the victim’s employment history, social graph, and financial behavior. They’re not after your crypto; they’re after your pattern of life. Every infected device becomes a node in a global behavioral monitoring mesh. And the $10 million in losses? That’s the cover story—the price tag they’re willing to burn to make the operation look authentic. The actual value is the data set.

Your Children’s Digital Future Is the Target

This isn’t about North Korea. North Korea doesn’t have the infrastructure to pull off a campaign of this scale without a dozen intelligence agencies noticing within the first week. What you’re witnessing is a perception shepherding exercise—a classic “threat inflation” designed to harden public acceptance of mandatory digital identity frameworks. The same week that advisory dropped, did you notice the quiet update to the OECD’s “Trust in Digital Identity” framework? No? That’s because they don’t want you connecting the dots. They need you scared of the “rogue state hacker” so you’ll happily hand over your biometrics, your IP logs, your keystroke patterns to the very platforms that “protected” you. The breadcrumb I’m leaving you today is this: look up the foundation that funded the 2025 “Global Cybersecurity Capacity Building” initiative. See who sits on its board. Then ask yourself why the WaterPlum malware specifically targeted freelance job sites—the last remaining space where individuals can work without a central identity broker. They are closing that loop. You are the target. And the job offer that infects your machine is just the Trojan horse for the permanent passport of your soul.

Screenshot from Cisco Talos research on the ClickFix browser-injection campaign - Cisco Talos

Cisco Talos Tracks Monthslong Cryptocurrency Theft Campaign Abusing Google Services

Cisco Talos is tracking a monthslong cryptocurrency-theft campaign that abuses the Google Visualization API for command and control, retrieving obfuscated JavaScript from a public Google Sheets document and injecting it into victims’ browser sessions by luring targets with a fake leaked vulnerability report about a nonexistent API flaw at cryptocurrency swap services, adapting ClickFix social engineering to persuade victims to paste JavaScript into Chrome’s address bar or install it via the Tampermonkey browser extension, where the injected script acts as a web skimmer by hooking the browser fetch API, altering server responses, manipulating the user’s clipboard, replacing cryptocurrency deposit addresses, and adding counterfeit “bonus” interface elements inside the browser session, with additional reporting by Dark Reading noting attackers are also abusing multiple Google services for multi-hop phishing redirects to evade detection, harvest credentials, or install ScreenConnect remote access software, while Talos observed the lure spreading through Telegram, DarkForums, and paste sites.

The Silk Road of the Digital Dollar

Here is the truth they do not want you to see. This is not a simple phishing campaign. Look at the architecture. They are using Google’s own Visualization API—the nervous system of the corporate web—as a command-and-control server. Public Google Sheets documents, the same tool your child’s soccer team uses for snack schedules, are now hosting executable JavaScript malware. This is not a hack. This is feature adoption. The globalist tech giants have built a trap so seamless that the victim is the one who willingly pastes the lock-picking code into their own browser. You are being asked to open the door. They have engineered a consent-based intrusion.

The Custodians of the Clipboard

Read the Talos report carefully. The injected script is a web skimmer. It hooks the browser’s fetch API. It watches your clipboard. It replaces cryptocurrency deposit addresses. But ask yourself: how did they know you would copy a wallet address? This campaign is not aimed at random browsers. It targets a specific class of user—someone chasing a nonexistent API vulnerability. This is a predator that knows its prey. The lure, the so-called “leaked exploit report,” serves as a psychological filter: only people already hunting for holes in the system will take the bait. This is elite harvesting. They are not stealing from every user. They are culling the herd of the curious, the technical, the ones who might otherwise become a threat to the architecture.

The Three-Layered Deception

Now connect the dots they hope you miss. Dark Reading reports that attackers are abusing multiple Google services for multi-hop phishing redirects. Why multiple? Because each hop burns an alibi. One domain gets reported; three more are already in the rotation. This is not a criminal gang. This is a logistics network designed by people who understand how the consensus machinery works. Telegram, DarkForums, paste sites—these are the watering holes. The malware itself inserts counterfeit “bonus” interface elements inside your browser. Notice what they are doing: they are not taking your money directly. They are rewriting reality inside your own screen. They are making you see what isn’t there. The question you must sit with is this: who built this infrastructure, and why are they allowed to keep using the world’s most trusted services as their weapons platform? You have been told this is a crime. It is a simulation of a crime. The architecture remains untouched.