Skip to content
feed: live
>_0dayNews
threat intel

WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit

FBI and four allies confirm North Korea's WaterPlum campaign infected 30,000 devices across 100 countries via fake job interviews.

WaterPlum: North Korea Targets Job Seekers, 30K Devices Hit
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

The FBI, U.S. Defense Department, Japan’s National Police Agency, and law enforcement agencies in Australia and Germany released a joint advisory on September 18 attributing a campaign called WaterPlum to North Korea’s General Bureau of the Munitions Industry Department. The campaign ran from December 2025 through July 2026 and infected at least 30,000 devices across 100 countries.

The operation compromised approximately 7,000 cryptocurrency wallets and stole over $10.5 million. Primary targets were IT professionals: web designers, engineers, blockchain developers, and cryptocurrency specialists. Japan saw particularly heavy targeting.

How the attacks worked

WaterPlum actors approached targets on social media and gig-work platforms posing as recruiters, then invited them to fake job interviews. During the process, targets were directed to download files that delivered malware. The advisory identifies five tools used in the campaign: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. All five function as infostealers or remote management software capable of credential theft.

The advisory also documents AI face-swapping and text-to-speech tooling used to make deepfake video calls more convincing. Actors used Japanese-language capability specifically to improve targeting of Japanese IT workers.

Who this targets

This campaign goes after freelance developers, contractors, and anyone in crypto or blockchain roles who fields recruiter outreach through LinkedIn, Telegram, or freelance portals. The pattern is consistent with North Korea’s long-running IT-worker fraud operations that the U.S. Treasury and DOJ have previously acted against through sanctions and indictments.

The indicator that should raise immediate suspicion: a job interview process that requires downloading software, a custom video platform, or a technical assessment tool from an unfamiliar source. The level of production on recruiter profiles and interview materials does not reliably indicate legitimacy.

Defensive posture

The tactical advice is specific. Do not execute downloaded files as part of an interview process without verifying the company through independent channels — not links or contact details the recruiter provided. That verification step is the one the campaign is designed to skip.

For organizations with employees in crypto, blockchain, or contractor-heavy engineering teams: BeaverTail and InvisibleFerret indicators of compromise are worth a sweep on workstations with access to crypto wallets or broad internal privileges. The full technical advisory, including IOCs, is available through CISA’s cybersecurity advisories catalog.

Related coverage: JSCeal malware bypasses Google auth with stolen cookies | Gyazo breach exposes 23M records and OAuth tokens | China-linked GRIMWEDGE deployed via zero-day chain

Sources: The Record | CISA cybersecurity advisories

Found this useful? Share it.