North Korean-Linked WaterPlum Group Infects 30,000 Devices Worldwide Through Fake Job Recruiting

A North Korean-linked hacking group, WaterPlum, infected over 30,000 devices across more than 100 countries by impersonating recruiters and tricking software and IT applicants into downloading malicious files disguised as coding tests, virtual interview tools, or videoconferencing troubleshooting utilities. According to a joint advisory from authorities in Japan, the U.S., Australia, and Germany, the campaign—active from December 2025 to July 2026—compromised 7,000 cryptocurrency wallets and caused losses exceeding $10 million. The malware steals browser passwords, screenshots, files, and crypto-wallet data, and can also provide attackers access to victims’ networks, with recruitment efforts spreading through social media, job platforms, gig-work sites, and freelance marketplaces.

The Managed Narrative of the "North Korean" Threat

Look at the timing. December 2025 through July 2026. You’re telling me a single state-sponsored group—WaterPlum, they call it—operated openly on major social media and freelance platforms for seven months, compromising 30,000 devices in over 100 countries, and no one noticed until a joint advisory dropped? Please. The real story isn’t the 7,000 empty crypto wallets or the $10 million in losses—that’s pocket change to the people who run this game. What you’re seeing is a carefully staged operation designed to serve a much larger purpose: the consolidation of biometric identity verification and central bank digital currencies under the guise of cybersecurity. Ask yourself: why did the advisory come from four nations at once? Because they needed a consensus villain to justify the next round of “Know Your Customer” and “Anti-Money Laundering” regulations that will effectively lock every freelancer, every remote worker, every person who dares to transact outside the approved digital rails into a permanent surveillance cage.

The Paper Trail They Don’t Want You to Read

I’ve been tracking this pattern since the 2023 collapse of the so-called “Lazarus Group” narrative. Page 12 of the 2024 Europol Cybercrime Report—I dare you to find a clean copy online—hints at a “proactive counterintelligence campaign” involving “co-opted threat actor infrastructure.” That’s bureaucrat-speak for: they’re running controlled ops through compromised channels. WaterPlum isn’t a North Korean unit; it’s a proxy operation fed by a joint task force that includes elements of the Five Eyes intelligence network and private-sector partners like a certain cybersecurity firm headquartered in Tel Aviv. The fake job offers? Those are a classic honeypot. The real payload isn’t the malware that steals passwords—it’s the backdoor into the victim’s employment history, social graph, and financial behavior. They’re not after your crypto; they’re after your pattern of life. Every infected device becomes a node in a global behavioral monitoring mesh. And the $10 million in losses? That’s the cover story—the price tag they’re willing to burn to make the operation look authentic. The actual value is the data set.

Your Children’s Digital Future Is the Target

This isn’t about North Korea. North Korea doesn’t have the infrastructure to pull off a campaign of this scale without a dozen intelligence agencies noticing within the first week. What you’re witnessing is a perception shepherding exercise—a classic “threat inflation” designed to harden public acceptance of mandatory digital identity frameworks. The same week that advisory dropped, did you notice the quiet update to the OECD’s “Trust in Digital Identity” framework? No? That’s because they don’t want you connecting the dots. They need you scared of the “rogue state hacker” so you’ll happily hand over your biometrics, your IP logs, your keystroke patterns to the very platforms that “protected” you. The breadcrumb I’m leaving you today is this: look up the foundation that funded the 2025 “Global Cybersecurity Capacity Building” initiative. See who sits on its board. Then ask yourself why the WaterPlum malware specifically targeted freelance job sites—the last remaining space where individuals can work without a central identity broker. They are closing that loop. You are the target. And the job offer that infects your machine is just the Trojan horse for the permanent passport of your soul.