North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as “WaterPlum,” which targets job seekers across more than 100 countries. This long-running cyber operation aims to infiltrate tech companies and generate illicit funds for the regime in Pyongyang. According to a recent advisory from the FBI, the Defense Department, and Japan’s National Police Agency, the WaterPlum group has been posing as AI and blockchain companies to deceive job applicants.
Between December 2025 and July 2026, the WaterPlum hackers infected at least 30,000 devices and compromised around 7,000 cryptocurrency wallets. The primary targets of this campaign include web designers, engineers, and cryptocurrency specialists, particularly in Japan. Job seekers are approached via social media, gig work websites, and freelance platforms, where they are instructed to download files during the interview process, leading to device infections and theft of sensitive information.
Japanese authorities have identified various malware strains, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, on the infected devices. These malware variants are typically used to install infostealers and remote management tools, allowing the hackers to maintain access to victim devices. In some cases, North Korean hackers have used stolen identity documents from victims to secure employment elsewhere.
Connections to IT Worker Schemes
The WaterPlum campaign is closely linked to broader schemes where North Koreans steal or purchase identities to secure lucrative positions in technology firms in the U.S. and Europe. Recently, Japanese officials disrupted a laptop farm operated by a Japanese national, uncovering evidence of significant financial transactions to addresses outside Japan. The FBI has also discovered numerous laptop farms in the U.S. that North Koreans use to create the illusion of local employment.
Reports indicate that WaterPlum actors and North Korean IT workers have utilized the same IP addresses when accessing these laptop farms or applying for positions at Japanese cryptocurrency companies. This disruption has provided insights into various North Korean cyber schemes, including the use of AI tools for face-swapping and text-to-speech software to enhance their deception.
The WaterPlum campaign and related IT worker schemes are reportedly managed by North Korea’s General Bureau of the Munitions Industry Department, which operates under the Central Committee of the Workers Party of Korea. Experts have noted that multiple government departments in North Korea run their own cyber units, engaging in activities ranging from legitimate IT work to cryptocurrency theft and data extortion.
For further details, refer to the advisory from the FBI and other agencies, which highlights the ongoing threat posed by North Korean cyber actors targeting job seekers and tech professionals.
For more information, see the full report by The Record.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



