North Korean cybercriminals, known as WaterPlum (formerly Contagious Interview), have infected over 30,000 devices in 100 countries, primarily targeting developers, web freelancers, and cryptocurrency professionals. A joint advisory from Japanese, U.S., Australian, and German authorities reveals that this activity spanned from December 2025 to July 2026. Investigators estimate that the operation generated JPY 1.7 billion, or approximately $10.71 million, in stolen cryptocurrency for the Democratic People’s Republic of Korea (DPRK).
North Korean WaterPlum Hackers Actors use social media, online job boards, gig-work platforms, recruiting services, and freelance marketplaces to impersonate legitimate AI, cryptocurrency, or NFT companies. During this process, attackers instruct candidates to download and execute files supposedly needed for testing, fixing a development environment, or resolving video conferencing issues.
Attackers can steal browser-stored authentication credentials, clipboard contents, keystrokes, screenshots, private keys, seed phrases from cryptocurrency wallets, and files from both local and shared folders. Attack Flow (Source: IC3) Investigators have linked WaterPlum's cyber activities to DPRK IT-worker operations, recognizing that these groups share infrastructure, including IP addresses used for accessing laptop farms, crowdsourcing services, and job applications. Laptop farms are locations where facilitators maintain devices and overseas workers operate them remotely, enabling them to appear in another country while performing contracted work.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.











