North Korean WaterPlum hackers infected 30,000 devices worldwide
- On Sept 18, Japan's National Police Agency and international partners including the FBI released findings uncovering the hacking group WaterPlum's methods, revealing direct links between its cyberattacks and North Korean IT worker operations under Bureau 313.
- The hacking group has compromised more than 30,000 devices across over 100 countries, stealing data from more than 7,000 cryptocurrency wallets after targeting developers through fake recruitment campaigns and malicious software like BeaverTail and InvisibleFerret.
- Associated with the 'Contagious Interview' threat, North Korean workers operate under Bureau 313, often resisting relocation while using VPN services to conceal their true locations during technical interviews.
- The Justice Department recently led enforcement efforts involving more than $7.74 million in digital assets, while two men received 18 month prison sentences in 2026 for assisting North Korean workers in accessing company laptops.
- Authorities urge employers to scrutinize candidates by verifying technical skills and ensuring stated residences match IP addresses, particularly when applicants resist relocation or demand cryptocurrency payments.
55 Articles
55 Articles
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
WaterPlum campaign tied to 30,000 infections across 100+ countries
A joint advisory from US, Japanese, Australian, and German authorities says North Korean group WaterPlum compromised at least 30,000 devices between Dec. 2025 and Jul. 2026, hit more than 7,000 crypto wallets, and moved $10.7 million...
North Korea's fake job interviews infected 30,000 devices
WaterPlum recruiters used bogus coding tests to backdoor jobseekers and raid more than 7,000 crypto wallets
FBI: This North Korean Group Infected 30,000 PCs To Steal Crypto
The FBI is warning about 'WaterPlum,' a hacking group out of North Korea that's been preying on job seekers looking for IT positions. The group will also apply for remote IT jobs too. A suspected North Korean hacking group has been blamed for infecting 30,000 PCs across the globe in an effort to steal cryptocurrency from unsuspecting users. On Friday, the FBI issued an alert about “WaterPlum,” a hacking group allegedly from North Korea that’s be…
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
International security agencies warned that North Korean hacker group WaterPlum is posing as prospective employers to target job seekers and steal millions in cryptocurrency.
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






















