Download Privacy Needle App

Type to search

Cybersecurity

North Korean WaterPlum Group Steals $10.7m in Global Crypto Campaign

Share

A joint international investigation has uncovered a widespread cyberattack campaign by the North Korean threat group WaterPlum, which infected at least 30,000 devices globally. The group, also referred to as Contagious Interview, is accused of stealing approximately $10.7 million (JPY 1.7bn) in cryptocurrency and compromising over 7,000 digital wallets.

The advisory, released by agencies including Japan’s National Police Agency (NPA), the FBI, and Australia’s ACSC, states the activity occurred between December 2025 and July 2026. Investigators have linked WaterPlum and certain North Korean IT workers to the 313 General Bureau, a unit operating under the Workers’ Party of Korea’s Munitions Industry Department.

Social Engineering via Fake Job Interviews

The attackers utilised sophisticated social engineering to target web designers, engineers, and Web3 specialists. By posing as employers from AI, cryptocurrency, or NFT companies, the actors recruited victims through social media platforms, job boards, and freelance marketplaces.

During technical interviews or coding assignments, victims were instructed to download and execute files hosted on various developer platforms. This process allowed the attackers to seed malicious NPM packages, including malware variants named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

StoatWaffle is specifically designed to exploit Visual Studio Code (VSC) projects. The malware can run code automatically once a user trusts a specific folder within the development environment. Once access was established, the attackers used remote access trojans (RATs) and infostealers to exfiltrate browser credentials, keystrokes, screenshots, and sensitive cryptocurrency data, including private keys and seed phrases.

The Role of Laptop Farms

The investigation highlights a significant overlap between the WaterPlum group and North Korean IT worker schemes. Threat actors used the same IP addresses to access “laptop farms”—locations where employment computers are managed remotely by North Korean workers—and to apply for positions at Japanese cryptocurrency exchanges.

To mask their locations, enablers provided identity documents, bank accounts, and virtual private servers (VPS) for these workers. Japanese authorities have already identified and dismantled at least one laptop farm located in Japan.

Security Recommendations

Security agencies have advised developers and organisations to adopt several defensive measures to mitigate the risk of similar campaigns:

  • Open unknown development projects in Visual Studio Code’s “Restricted Mode”.
  • Carefully inspect any tasks.json files before executing code.
  • Limit contractor access to sensitive source code and credentials.
  • Perform rigorous identity verification for all new applicants and downstream subcontractors.
Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.