Adversary Intelligence — 2026-09-21

FBI and Allied Agencies Jointly Attribute North Korean WaterPlum Job-Seeker Malware Campaign Infecting 30000 Devices Across 100 Countries

BLUFFormal attribution linking WaterPlum malware to North Korea's munitions bureau collapses the distinction between cyber espionage and sanctions evasion, placing commercial hiring pipelines and open-source repositories on the front line.

The FBI, DoD Cyber Crime Center, and cybersecurity agencies in Japan, Australia, and Germany jointly attributed a North Korean hacking campaign tracked as WaterPlum or Contagious Interview to the 313 General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea's Central Committee . The joint advisory, published Friday, states the group poses as employers, often impersonating AI, cryptocurrency, or NFT firms, to target software developers and IT professionals with fake job interviews, using AI face-swapping software plus AI-generated Japanese speech and translation tools to pass convincingly as interviewers on video calls 12. Agencies report WaterPlum infected more than 30,000 devices across over 100 countries and moved roughly $11 million in cryptocurrency from more than 7,000 wallets to North Korea during a campaign running from December 2025 through July 2026 12. The advisory also states WaterPlum actors share IP infrastructure with separate North Korean IT-worker schemes, including access to the same laptop farms and job applications at a Japanese crypto exchange, and notes Japanese authorities dismantled a laptop farm run by a Japanese national and traced several hundred million yen in transfers tied to the group 1. Victim devices were found carrying malware strains including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle 12.

Analysis
The joint advisory formalizes what open-source trackers described piecemeal since 2023: Contagious Interview functions as an operating arm of North Korea's sanctioned IT-worker export apparatus rather than a discrete hacking campaign, fusing credential theft with illicit overseas employment. Shared IP infrastructure linking WaterPlum to crowdsourcing-platform accounts and laptop farms indicates the same operator pool runs both the malware lures and the freelance-contract fraud funding weapons programs, shifting exposure from government networks to hiring pipelines, npm registries, and extension marketplaces that now function as sanctioned-actor infrastructure. The FBI/IC3 advisory, co-issued with Japanese, Australian, and German counterparts, is the sole primary source; wire outlets republish its figures without independent corroboration. The 30,000-device, 100-country, $11 million tally may reflect cumulative activity tracked since 2023 rather than a discrete surge within this reporting window. Recruiters and individual developers, not just enterprise security teams, now sit on the front line of this sanctions-evasion economy.
9 sources
  1. International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data - CyberScoop
  2. North Korean hackers infect thousands of devices across 100 countries as part of 'WaterPlum' campaign - The Record (Recorded Future News)
  3. IC3: North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto - Rankiteo Blog
  4. North Korean WaterPlum hackers infected 30,000 devices worldwide - BleepingComputer
  5. North Korea's fake job interviews infected 30,000 devices - The Register
  6. North Korea's fake job interviews infected 30,000 devices - The Register
  7. North Korean fake recruiters infect 30,000 devices worldwide - Cybernews
  8. North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs - Tom's Hardware
  9. North Korean "WaterPlum," commonly referred to as "Contagious Interview," cyber actor group targeting IT professionals - FBI/IC3 (joint Cybersecurity Advisory with Japan's National Police Agency & National Cybersecurity Office, Australia's ACSC, Germany's BfV/BND, and the U.S. DoD Cyber Crime Center)

View in full brief →

UNCLASSIFIED // OPEN SOURCE