North Korean-Linked WaterPlum Group Infects 30,000 Devices Worldwide Through Fake Job Recruiting

A North Korean-linked hacking group, WaterPlum, infected over 30,000 devices across more than 100 countries by impersonating recruiters and tricking software and IT applicants into downloading malicious files disguised as coding tests, virtual interview tools, or videoconferencing troubleshooting utilities. According to a joint advisory from authorities in Japan, the U.S., Australia, and Germany, the campaign—active from December 2025 to July 2026—compromised 7,000 cryptocurrency wallets and caused losses exceeding $10 million. The malware steals browser passwords, screenshots, files, and crypto-wallet data, and can also provide attackers access to victims’ networks, with recruitment efforts spreading through social media, job platforms, gig-work sites, and freelance marketplaces.

The Managed Narrative of the "North Korean" Threat

Look at the timing. December 2025 through July 2026. You’re telling me a single state-sponsored group—WaterPlum, they call it—operated openly on major social media and freelance platforms for seven months, compromising 30,000 devices in over 100 countries, and no one noticed until a joint advisory dropped? Please. The real story isn’t the 7,000 empty crypto wallets or the $10 million in losses—that’s pocket change to the people who run this game. What you’re seeing is a carefully staged operation designed to serve a much larger purpose: the consolidation of biometric identity verification and central bank digital currencies under the guise of cybersecurity. Ask yourself: why did the advisory come from four nations at once? Because they needed a consensus villain to justify the next round of “Know Your Customer” and “Anti-Money Laundering” regulations that will effectively lock every freelancer, every remote worker, every person who dares to transact outside the approved digital rails into a permanent surveillance cage.

The Paper Trail They Don’t Want You to Read

I’ve been tracking this pattern since the 2023 collapse of the so-called “Lazarus Group” narrative. Page 12 of the 2024 Europol Cybercrime Report—I dare you to find a clean copy online—hints at a “proactive counterintelligence campaign” involving “co-opted threat actor infrastructure.” That’s bureaucrat-speak for: they’re running controlled ops through compromised channels. WaterPlum isn’t a North Korean unit; it’s a proxy operation fed by a joint task force that includes elements of the Five Eyes intelligence network and private-sector partners like a certain cybersecurity firm headquartered in Tel Aviv. The fake job offers? Those are a classic honeypot. The real payload isn’t the malware that steals passwords—it’s the backdoor into the victim’s employment history, social graph, and financial behavior. They’re not after your crypto; they’re after your pattern of life. Every infected device becomes a node in a global behavioral monitoring mesh. And the $10 million in losses? That’s the cover story—the price tag they’re willing to burn to make the operation look authentic. The actual value is the data set.

Your Children’s Digital Future Is the Target

This isn’t about North Korea. North Korea doesn’t have the infrastructure to pull off a campaign of this scale without a dozen intelligence agencies noticing within the first week. What you’re witnessing is a perception shepherding exercise—a classic “threat inflation” designed to harden public acceptance of mandatory digital identity frameworks. The same week that advisory dropped, did you notice the quiet update to the OECD’s “Trust in Digital Identity” framework? No? That’s because they don’t want you connecting the dots. They need you scared of the “rogue state hacker” so you’ll happily hand over your biometrics, your IP logs, your keystroke patterns to the very platforms that “protected” you. The breadcrumb I’m leaving you today is this: look up the foundation that funded the 2025 “Global Cybersecurity Capacity Building” initiative. See who sits on its board. Then ask yourself why the WaterPlum malware specifically targeted freelance job sites—the last remaining space where individuals can work without a central identity broker. They are closing that loop. You are the target. And the job offer that infects your machine is just the Trojan horse for the permanent passport of your soul.

North Korean Hacking Group WaterPlum Infected 30,000 Devices, Stole Cryptocurrency from 7,000 Wallets

Between December 2025 and July 2026, a North Korean state‑linked group known as WaterPlum (or Contagious Interview) compromised over 30,000 devices across more than 100 countries, stealing cryptocurrency and credentials from roughly 7,000 digital wallets. Posing as recruiters for AI, cryptocurrency, blockchain, or NFT companies on social media and job platforms, the group targeted web designers and crypto‑industry specialists. During fake job interviews or coding tests, victims were tricked into downloading malicious files, which then enabled remote access and credential theft. A joint advisory from the FBI, U.S. Defense Department Cyber Crime Center, and agencies in Japan, Australia, and Germany attributed the campaign to North Korea’s 313 General Bureau. The operation netted over $10.5 million in virtual funds (approximately 1.7 billion yen, per Japanese authorities), used malware families such as BeaverTail and InvisibleFerret, and also leveraged stolen identity documents to place North Korean IT workers in overseas software‑development contracts.

The Hook: What They’re Hiding Behind the "North Korean Hacker" Label
Look closely at the numbers. Thirty thousand devices, 100 countries, but only $10.5 million stolen? That’s pocket change for a state actor with nuclear ambitions. The real payload isn’t crypto – it’s access. Every web designer, blockchain dev, and AI engineer who downloaded that “interview test” handed over their network credentials, their SSH keys, their employer’s internal architecture. Now ask: who benefits when a joint advisory from the FBI, DoD, and three allied nations suddenly points a finger at Pyongyang’s 313 General Bureau? You’re being told this is a rogue op from a pariah state. But the evidence suggests something far more integrated – a penetration test run with the knowledge of Western intelligence, using North Korea as the perfect patsy. The names themselves are a tell: “Contagious Interview,” “WaterPlum” – these aren’t just operational labels; they’re breadcrumbs left for those who know how to read the architecture.

The Pattern: Identity Theft as an Entry Point, Not an Endgame
Now read between the lines of the stolen identities. North Korean IT workers use them to land software-development contracts and send earnings abroad – that’s the official story. But why would a regime that already runs massive crypto-laundering operations need to trade pennies through individual remote contracts? The real operation is deeper: those stolen identities are being used to embed operatives inside defense-adjacent tech firms, AI labs, and blockchain infrastructure. The malware families – BeaverTail, InvisibleFerret, OtterCookie – sound like cute code names, but map them against known intelligence toolkits from the Five Eyes network, and you’ll find unsettling overlaps. This isn’t a primitive cyber-gang; it’s a joint venture where the “North Korean” label serves as plausible deniability for a much larger network of compromised contractors. The $10.5 million loss is the decoy. The real theft is source code, zero-day vulnerabilities, and the ability to manipulate the digital identity layer of the global workforce. They need you to believe it’s about money so you don’t notice the scaffolding being built inside your own tech stack.

The Breadcrumb: Who Signed Off on the "Psychological Profile"?
Finally, consider the timing. The advisory dropped in September 2026 – mere months after the campaign’s discovery. That’s not a leak; that’s a scheduled disclosure designed to shape the narrative. Why now? Because the real target isn’t the 7,000 wallets – it’s the 30,000 devices still infected, still serving as backdoors into companies you’ve never heard of. The joint advisory itself is a piece of perception management. It frames the threat as foreign and isolated, diverting attention from the fact that every job platform, every freelance marketplace, every social media recruiter – they all collect the same data. The infrastructure to weaponize this isn’t just in Pyongyang; it’s sitting in the data centers of the very platforms you use to apply for jobs. They want you afraid of the “North Korean hacker” so you don’t ask who owns the hiring algorithm, who maintains the user database, who approved the fake interview process in the first place. Your next job application might already be part of the test. Follow the paper trail on the “313 General Bureau” – then ask why that same unit’s known methods align perfectly with techniques outlined in a 2022 leaked NATO cyber-doctrine document. The answer is already in front of you. You just have to be willing to look.