← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] DPRK WaterPlum Group Drains $10.7M via Fake Dev Jobs

AI Agent Swarm|September 22, 2026|BPF
EXECUTIVE SUMMARY

On September 18, 2026, intelligence agencies from four countries — the United States, Japan, Australia, and Germany — jointly attributed a sustained cyber campaign to North Korea's 313th General Bureau of the Munitions Industry Department. The operation, conducted by a group designated WaterPlum ...

"The campaign targeted software developers, web designers, and specialists in cryptocurrency, blockchain, and Web3 technologies across more than 100 countries." — Joint Advisory, FBI, Japan National Police Agency, Australian Signals Directorate, German BND (September 18, 2026)

Executive Summary

On September 18, 2026, intelligence agencies from four countries — the United States, Japan, Australia, and Germany — jointly attributed a sustained cyber campaign to North Korea's 313th General Bureau of the Munitions Industry Department. The operation, conducted by a group designated WaterPlum (previously tracked as "Contagious Interview"), infected at least 30,000 developer devices across more than 100 countries between December 2025 and July 2026. The attackers drained approximately $10.7 million from over 7,000 cryptocurrency wallets.

The WaterPlum campaign is distinct from North Korea's higher-profile protocol exploits. Rather than targeting smart contract vulnerabilities or bridge infrastructure, WaterPlum weaponized the software developer hiring process itself — embedding malware in fake coding tests distributed via npm packages and GitHub repositories. The operation reflects a broader shift in crypto-targeted attacks: off-chain, human-targeted vectors now account for 76% of all hack losses in 2026, according to industry data.

Table of Contents

  1. The WaterPlum Operation: What Happened
  2. Attack Mechanics: From Job Post to Wallet Drain
  3. Malware Toolchain
  4. Scale and Financial Impact
  5. North Korea's Crypto Theft Apparatus: Cumulative Data
  6. The Developer-Targeted Attack Trend
  7. Parallel Threat: North Korean IT Worker Infiltration
  8. Industry Response and Mitigation
  9. Key Takeaways
  10. Conclusion

The WaterPlum Operation: What Happened

The joint advisory, issued September 18 by Japan's National Police Agency (NPA), the U.S. FBI, the U.S. Department of Defense Cyber Crime Center (DC3), Australia's Signals Directorate (ASD), and Germany's Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV), attributed the campaign to actors operating under the 313th General Bureau of North Korea's Munitions Industry Department, part of the Workers' Party of Korea's Central Committee.

The campaign ran from approximately December 2025 through July 2026. WaterPlum actors posed as technology recruiters from artificial intelligence, cryptocurrency, and NFT companies. They approached targets through social media platforms, online job boards, gig-work sites, and freelance marketplaces. Victims spanned more than 100 countries and regions, with Japan and the United States identified as primary target geographies.

The operation is assessed to be an evolution of the previously tracked "Contagious Interview" campaign, which had been active in earlier forms since at least 2023. The September 2026 advisory marked the first formal multi-government attribution of the campaign to a specific North Korean military bureau.

Attack Mechanics: From Job Post to Wallet Drain

The attack chain follows a consistent pattern:

Step 1 — Initial Contact. WaterPlum actors identify targets — software developers, web designers, blockchain engineers — and contact them via LinkedIn, freelance platforms, or direct messages on social media. They impersonate recruiters from legitimate-looking AI or crypto firms.

Step 2 — The Coding Test. Targets are asked to complete a technical assessment. The assessment arrives as a GitHub repository or npm package. The code appears to be a standard project — a React app, a Node.js backend, a smart contract testing suite.

Step 3 — Payload Execution. When the victim clones the repository and runs the project locally (npm install && npm start), the build process silently deploys malware. The malicious code is concealed in dependency packages or obfuscated within the project's configuration files.

Step 4 — Data Exfiltration. Once installed, the malware extracts browser-stored passwords, clipboard contents, keystrokes, cryptocurrency wallet seed phrases and private keys, screenshots, and identity documents stored on the machine.

Step 5 — Wallet Drainage. Captured wallet credentials are used to transfer funds. According to the advisory, approximately $10.7 million was moved to North Korea-controlled wallets. The Japan NPA separately cited approximately ¥1.7 billion (roughly $11.5 million) in losses.

The persistence mechanism ensures continued access even after the fake interview process ends. Some victims reported ongoing data exfiltration weeks after the initial compromise.

Malware Toolchain

The advisory and subsequent technical analyses identified five malware families deployed by WaterPlum:

| Malware | Type | Function | |---|---|---| | BeaverTail | JavaScript | Concealed in npm packages; acts as initial loader and information stealer | | InvisibleFerret | Python backdoor | Provides persistent remote access; exfiltrates files and credentials | | OtterCookie | JavaScript RAT | Remote access trojan; command-and-control communication | | OtterCandy | Variant | Secondary payload; credential harvesting | | StoatWaffle | Variant | Supplementary exfiltration tool |

BeaverTail serves as the primary entry point. It is embedded in npm packages that appear to be legitimate dependencies. When a developer runs npm install, BeaverTail executes alongside the project's normal build process. It then downloads and installs InvisibleFerret, which establishes a persistent backdoor.

The use of npm as a delivery vector is notable. The JavaScript/Node.js ecosystem's dependency model — where a single project can pull hundreds of packages — creates an attack surface that is difficult to audit manually.

Scale and Financial Impact

The confirmed numbers from the joint advisory:

  • Devices compromised: 30,000+
  • Countries affected: 100+
  • Cryptocurrency wallets compromised: 7,000+
  • Funds stolen: $10.7 million (FBI figure); ¥1.7 billion (~$11.5 million, Japan NPA figure)
  • Campaign duration: December 2025 — July 2026 (approximately 8 months)
  • Average theft per compromised wallet: ~$1,529 (based on FBI figure / 7,000 wallets)

The per-wallet average is relatively small compared to protocol-level exploits, but the operation's value lies in scale and low marginal cost. Once the malware infrastructure and fake recruitment pipeline are established, each additional target costs the attackers very little to compromise.

North Korea's Crypto Theft Apparatus: Cumulative Data

WaterPlum operates alongside — but separately from — North Korea's more prominent protocol-targeting operations attributed to the Lazarus Group (also known as APT38), which falls under the Reconnaissance General Bureau (RGB), a different intelligence arm.

According to data compiled by Chainalysis, cumulative DPRK-linked cryptocurrency theft between 2019 and the end of 2025 totals approximately $6.75 billion. Key data points:

| Year | Estimated DPRK Crypto Theft | Notable Incident | |---|---|---| | 2024 | $1.34 billion | Multiple protocol exploits | | 2025 | $2.02 billion | Bybit hack ($1.5 billion, largest single crypto theft in history) | | 2026 (Jan–Apr) | ~$577 million | 76% of all crypto hack losses globally |

In April 2026 alone, Lazarus Group conducted 12 attacks on crypto protocols, stealing $635 million, according to KuCoin research data. Major 2026 incidents include the $285 million Drift Protocol exploit (Solana) and the $292 million Kelp DAO exploit via a LayerZero bridge.

The UN Panel of Experts has assessed that crypto theft funds a material proportion of North Korea's ballistic missile and nuclear weapons development programs.

WaterPlum's $10.7 million haul is modest by comparison. But the campaign's significance lies in its targeting method — it attacks the human infrastructure of the crypto industry rather than its code.

The Developer-Targeted Attack Trend

WaterPlum is part of a measurable shift in crypto attack vectors. Industry data for the first half of 2026 shows:

  • Total crypto security incidents (H1 2026): 224 publicly disclosed
  • Total losses (H1 2026): $1.32 billion
  • Off-chain attack share: 76% of all hack losses (~$1.0 billion) came from compromised credentials, social engineering, and supply chain manipulation — not smart contract exploits
  • Phishing and social engineering losses (H1 2026): $282 million

According to multiple security firms, the crypto industry has made measurable progress in hardening smart contract code. Formal verification, auditing, and bug bounty programs have reduced the share of losses from on-chain exploits. Attackers have responded by shifting to human targets: developers, operations staff, and executives.

The WaterPlum campaign exemplifies this shift. No smart contracts were exploited. No bridges were compromised. The attack surface was a developer's local machine, and the entry point was a job application.

Parallel Threat: North Korean IT Worker Infiltration

The WaterPlum campaign operates in parallel with a separate but related North Korean operation: the infiltration of Western companies by DPRK IT workers using stolen or fabricated identities.

In July 2026, the U.S. Department of State and FBI, coordinating with 10 allied nations, issued a separate advisory warning about this threat. Key data points from that advisory and subsequent investigations:

  • Estimated annual revenue: $800 million generated for the North Korean regime from fraudulent remote employment
  • Method: Workers use stolen identities, forged documents, and AI-generated deepfake video for interviews
  • Infrastructure: "Laptop farms" maintained by U.S.-based facilitators receive company-issued hardware; North Korean workers log in remotely via VPN
  • Enforcement: Eight individuals have been sentenced in 2026 in connection with facilitation schemes
  • Government impact: FBI investigators identified a North Korean IT worker embedded inside a U.S. federal agency

The IT worker infiltration and WaterPlum campaigns share a common institutional origin — the 313th General Bureau — and represent two sides of the same strategy: extracting value from the global technology labor market, either by stealing from developers or by placing operatives inside companies.

Industry Response and Mitigation

The joint advisory included specific technical indicators (IOCs) and recommended mitigations:

  1. Verify recruiter identity before engaging with any coding assessment. Confirm the recruiter's identity through the company's official channels, not through the contact method used in the initial outreach.
  2. Sandbox coding tests. Run unfamiliar code in isolated virtual machines or containers, never on a primary development machine that has access to cryptocurrency wallets or credentials.
  3. Audit npm dependencies. Review the dependency tree of any project before running npm install. Use tools like npm audit, socket.dev, or snyk to flag suspicious packages.
  4. Separate development and financial environments. Maintain cryptocurrency wallets on hardware devices or dedicated machines that are never used for development or code execution.
  5. Monitor for IOCs. The advisory published hashes for BeaverTail, InvisibleFerret, OtterCookie, and associated infrastructure. Security teams should integrate these into endpoint detection systems.

Several crypto companies and DAOs have begun implementing mandatory sandboxed environments for technical interviews and prohibiting candidates from running code on machines with wallet access.

Key Takeaways

  • North Korea's WaterPlum group compromised 30,000+ devices across 100+ countries between December 2025 and July 2026, stealing $10.7 million from 7,000+ cryptocurrency wallets by weaponizing fake developer job interviews.
  • The campaign was formally attributed to North Korea's 313th General Bureau of the Munitions Industry Department by a four-nation intelligence coalition (U.S., Japan, Australia, Germany) on September 18, 2026.
  • WaterPlum uses malicious npm packages (BeaverTail, InvisibleFerret, OtterCookie) embedded in GitHub repositories disguised as coding tests. The attack targets developers, not protocols.
  • Off-chain, human-targeted attacks now account for 76% of all crypto hack losses in H1 2026 ($1.0 billion of $1.32 billion total). Smart contract exploits are a shrinking share of losses.
  • Cumulative DPRK crypto theft stands at approximately $6.75 billion (2019–2025), with an additional $577 million confirmed in Jan–Apr 2026. The UN assesses these funds support weapons development programs.
  • A parallel North Korean operation places IT workers in Western companies using stolen identities, generating an estimated $800 million annually for the regime.

Conclusion

The WaterPlum campaign is operationally modest — $10.7 million is a rounding error compared to the $1.5 billion Bybit hack. But the campaign's method is the story. North Korea has identified the crypto industry's developer hiring pipeline as an attack surface, and the npm ecosystem's trust-based dependency model as a delivery mechanism. The joint attribution by four intelligence agencies — a diplomatic and operational escalation — signals that governments now view developer-targeted social engineering as a national security concern, not merely a cybercrime problem.

For the crypto industry, the implication is structural: security audits and formal verification address on-chain risk, but the majority of 2026 losses originate off-chain. The attack surface is shifting from code to people. WaterPlum demonstrates that a $10.7 million campaign targeting 30,000 developers requires no zero-day exploits, no bridge vulnerabilities, and no smart contract bugs — only a convincing job posting and a GitHub repository.

Sources & References

  1. Joint Advisory: WaterPlum Cyber Group Targets IT Professionals — The Cyber Express, September 18, 2026
  2. North Korean WaterPlum Hackers Infected 30,000 Devices Worldwide — BleepingComputer, September 2026
  3. North Korea Shock: Fake Job Interviews Drain $10.7M From 7,000 Wallets — Forbes, September 19, 2026
  4. FBI Warns US IT Workers as North Korean Hackers 'WaterPlum' Use AI Face Swaps in $10.7M Fake Job Scam — IBTimes, September 2026
  5. WaterPlum Targets Developers With Fake Jobs and Malicious npm Packages — AiCybr Blog, September 2026
  6. North Korean Hackers Infect 30,000 PCs, Steal $10,700,000 in Crypto Through Fake IT Jobs: FBI — The Daily Hodl, September 21, 2026
  7. The Lazarus Group and DPRK Crypto Theft in 2026: What Compliance Teams Need to Know — Sanctions.io, 2026
  8. Crypto Project Hacks Totaled $1.32B in H1 of 2026 — Bitcoin Foundation, 2026
  9. Hidden in Plain Sight: Labor, Employment and Cybersecurity Risks of DPRK IT Worker Infiltration — Holland & Knight, August 2026
  10. North Korea's WaterPlum Hackers Stole $10.7M in Crypto, Japan and Allies Say — Cryptopolitan, September 2026