North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as “WaterPlum,” which targets job seekers across more than 100 countries. This long-running cyber operation aims to infiltrate tech companies and generate illicit funds for the regime in Pyongyang. According to a recent advisory from the FBI, the Defense Department, and Japan’s National Police Agency, the WaterPlum group has been posing as AI and blockchain companies to deceive job applicants.

Between December 2025 and July 2026, the WaterPlum hackers infected at least 30,000 devices and compromised around 7,000 cryptocurrency wallets. The primary targets of this campaign include web designers, engineers, and cryptocurrency specialists, particularly in Japan. Job seekers are approached via social media, gig work websites, and freelance platforms, where they are instructed to download files during the interview process, leading to device infections and theft of sensitive information.

Japanese authorities have identified various malware strains, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, on the infected devices. These malware variants are typically used to install infostealers and remote management tools, allowing the hackers to maintain access to victim devices. In some cases, North Korean hackers have used stolen identity documents from victims to secure employment elsewhere.

Connections to IT Worker Schemes

The WaterPlum campaign is closely linked to broader schemes where North Koreans steal or purchase identities to secure lucrative positions in technology firms in the U.S. and Europe. Recently, Japanese officials disrupted a laptop farm operated by a Japanese national, uncovering evidence of significant financial transactions to addresses outside Japan. The FBI has also discovered numerous laptop farms in the U.S. that North Koreans use to create the illusion of local employment.

Reports indicate that WaterPlum actors and North Korean IT workers have utilized the same IP addresses when accessing these laptop farms or applying for positions at Japanese cryptocurrency companies. This disruption has provided insights into various North Korean cyber schemes, including the use of AI tools for face-swapping and text-to-speech software to enhance their deception.

The WaterPlum campaign and related IT worker schemes are reportedly managed by North Korea’s General Bureau of the Munitions Industry Department, which operates under the Central Committee of the Workers Party of Korea. Experts have noted that multiple government departments in North Korea run their own cyber units, engaging in activities ranging from legitimate IT work to cryptocurrency theft and data extortion.

For further details, refer to the advisory from the FBI and other agencies, which highlights the ongoing threat posed by North Korean cyber actors targeting job seekers and tech professionals.

For more information, see the full report by The Record.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

UAE Cyber Security Council and Fortinet Launch Internship Program for Emirati Students

The UAE Cyber Security Council (CSC) has partnered with Fortinet to launch a new cybersecurity internship programme aimed at equipping Emirati university students with...

AWS AgentCore Harness Vulnerability Allows Credential Exfiltration via Prompt Injection

Recent research from Unit 42 has uncovered a significant vulnerability in Amazon Web Services (AWS) AgentCore Harness, which could allow attackers to exfiltrate plaintext...

Germany’s F127 frigate program faces scrutiny over U.S. technology reliance

Germany's F127 frigate program faces scrutiny over U.S. technology reliance The German Navy's future F127 class air defense frigates are set to be equipped with...

Researchers Exploit OpenAI Forum Flaw to Access Internal ChatGPT Account

Researchers have exploited a vulnerability in OpenAI's community forum, hosted by Discourse, to gain unauthorized access to an internal ChatGPT account belonging to an...