North Korean WaterPlum Group Steals $10.7m in Global Crypto Campaign
Share
A joint international investigation has uncovered a widespread cyberattack campaign by the North Korean threat group WaterPlum, which infected at least 30,000 devices globally. The group, also referred to as Contagious Interview, is accused of stealing approximately $10.7 million (JPY 1.7bn) in cryptocurrency and compromising over 7,000 digital wallets.
The advisory, released by agencies including Japan’s National Police Agency (NPA), the FBI, and Australia’s ACSC, states the activity occurred between December 2025 and July 2026. Investigators have linked WaterPlum and certain North Korean IT workers to the 313 General Bureau, a unit operating under the Workers’ Party of Korea’s Munitions Industry Department.
Social Engineering via Fake Job Interviews
The attackers utilised sophisticated social engineering to target web designers, engineers, and Web3 specialists. By posing as employers from AI, cryptocurrency, or NFT companies, the actors recruited victims through social media platforms, job boards, and freelance marketplaces.
During technical interviews or coding assignments, victims were instructed to download and execute files hosted on various developer platforms. This process allowed the attackers to seed malicious NPM packages, including malware variants named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
StoatWaffle is specifically designed to exploit Visual Studio Code (VSC) projects. The malware can run code automatically once a user trusts a specific folder within the development environment. Once access was established, the attackers used remote access trojans (RATs) and infostealers to exfiltrate browser credentials, keystrokes, screenshots, and sensitive cryptocurrency data, including private keys and seed phrases.
The Role of Laptop Farms
The investigation highlights a significant overlap between the WaterPlum group and North Korean IT worker schemes. Threat actors used the same IP addresses to access “laptop farms”—locations where employment computers are managed remotely by North Korean workers—and to apply for positions at Japanese cryptocurrency exchanges.
To mask their locations, enablers provided identity documents, bank accounts, and virtual private servers (VPS) for these workers. Japanese authorities have already identified and dismantled at least one laptop farm located in Japan.
Security Recommendations
Security agencies have advised developers and organisations to adopt several defensive measures to mitigate the risk of similar campaigns:
- Open unknown development projects in Visual Studio Code’s “Restricted Mode”.
- Carefully inspect any
tasks.jsonfiles before executing code. - Limit contractor access to sensitive source code and credentials.
- Perform rigorous identity verification for all new applicants and downstream subcontractors.




Leave a Reply