
Key Summary
- The North Korean hacking group WaterPlum infected at least 30,000 devices across more than 100 countries during an eight-month period from December 2025 to July 2026, according to a joint advisory issued by investigative authorities from Japan, the U.S., Australia, and Germany.
- The attack is confirmed to have compromised more than 7,000 cryptocurrency wallets, with approximately 1.7 billion yen (about $10.71 million) in crypto assets funneled to North Korea.
- WaterPlum used job-seeking and recruitment activity as bait. The group reportedly impersonated real AI, cryptocurrency, and non-fungible token (NFT) companies, or approached victims through legitimate recruitment and freelance platforms.
News-summary style. Compressed coverage of new cyber threat information focused on key facts, alongside threat characteristics and implications that practitioners can immediately reference.
Table of Contents
- Key Summary
- Why Four Countries’ Investigative Authorities Issued the WaterPlum Advisory Simultaneously
- The WaterPlum Attack Path: 3 Stages of ‘Company Impersonation → Interview → Code Execution’
- Why the WaterPlum Case Is Dangerous Right Now
- What to Do Right Now
- Practical Application Points
- Frequently Asked Questions
- Source Material
“It’s an interview—please run this code.” That single line infected 30,000 devices.
Over an eight-month period from December 2025 to July 2026, the North Korean hacking group WaterPlum infected at least 30,000 devices across more than 100 countries. This was revealed in a joint advisory issued by investigative authorities from Japan, the U.S., Australia, and Germany.
The most shocking element is the method. WaterPlum impersonated real companies in the AI, cryptocurrency, and non-fungible token (NFT) sectors, or approached job seekers through recruitment and freelance platforms. The group then dangled a “fake interview” as bait. During the interview process, victims were instructed to install specific software or run code, allowing malware to infiltrate their systems.
More than 7,000 cryptocurrency wallets are confirmed to have been compromised in the attack. The stolen crypto is valued at approximately 1.7 billion yen, or $10.71 million. This is not a simple case of personal data breach; real assets were systematically transferred to North Korea.
This, in the author’s view, is the most significant point: the “everyday attack surface.” The act of looking for or offering a job—something everyone does—has itself become an attack vector. It’s not phishing emails, nor is it a vulnerability exploit. This is an extreme example of social engineering that preys on the moment when a person does not suspect another person.
Why Four Countries’ Investigative Authorities Issued the WaterPlum Advisory Simultaneously
The fact that not just one country, but four nations simultaneously issued an advisory demonstrates the scale of WaterPlum’s operational reach. The spread of infected devices across 100 countries means that the target was not a specific region but the global pool of job seekers.
The joining of forces by Japan, the U.S., Australia, and Germany appears to reflect the limits of any single nation’s ability to trace funds internationally and disrupt attack infrastructure. Because cryptocurrency is inherently borderless, the money moves quickly regardless of where victims are located.
The WaterPlum Attack Path: 3 Stages of ‘Company Impersonation → Interview → Code Execution’
The WaterPlum attack is broadly divided into three stages.
First, the group impersonated real AI, crypto, and NFT companies, or exploited legitimate hiring platforms to approach job seekers. Second, under the pretext of a video or technical interview, they required the installation of specific programs or the execution of code from GitHub or similar sources. Third, they planted a backdoor on the victim’s device to maintain long-term access, then drained crypto wallets.
What stands out to practitioners is that the “technical interview” setting provided WaterPlum with the perfect excuse. Asking a developer job seeker to execute code is not inherently suspicious in itself. That is likely why this attack was able to accumulate damage over eight months.
| Stage | Action | Result |
|---|---|---|
| 1. Approach | Impersonate real companies; abuse hiring platforms | Gain job seeker’s trust |
| 2. Infiltration | Coerce code/software execution during technical interview | Malware infiltration |
| 3. Theft | Long-term backdoor persistence, then wallet data exfiltration | Crypto asset outflow |
Why the WaterPlum Case Is Dangerous Right Now
North Korea’s cryptocurrency theft has long been established as a core means of foreign currency acquisition. The WaterPlum case stands apart from prior incidents on two axes: scale and international coordination.
- Infected devices: at least 30,000
- Countries affected: 100+
- Wallets stolen: 7,000+
- Amount stolen: approximately 1.7 billion yen ($10.71 million)
- Attack period: 8 months (Dec 2025 – Jul 2026)
Most victims likely lost wallet assets without ever realizing they had been infected. A significant time gap typically exists between the moment malware infiltrates a system and the actual theft of assets.
What to Do Right Now
- Before any interview, cross-verify the company’s domain and business registration through official channels.
- If you are asked to install video interview tools or run external code, report it to your IT security team immediately.
- Separate your crypto wallets into cold and hot wallets, and implement multi-signature (multisig).
- Install EDR products on developer devices, and run sandbox checks on any cloned repositories from GitHub or other external sources.
- Run all files received during a hiring process through static and dynamic analysis on services like VirusTotal before submission.
Practical Application Points
WaterPlum’s method differs in dimension from typical malware response because it targets “what humans do most naturally.” Relying solely on technical controls will not stop this attack. Security verification steps must be embedded directly into the business processes of hiring and interviewing.
- Recruiters: Standardize procedures to reject or require IT team verification for any requests to install video interview tools, execute code, or grant remote access.
- Security practitioners: Establish detection rules to monitor tokens and session information being exfiltrated from job seeker devices.
- Job seekers: Never store wallet seed phrases digitally, and use a laptop dedicated to interviews that is separate from your work device.
Frequently Asked Questions
What kind of organization is WaterPlum?
WaterPlum is a North Korean hacking group, officially named in this four-country joint advisory. Its defining characteristic is the targeting of global job seekers using recruitment activity as bait.
How does the fake interview attack proceed?
The group offers a fake interview by impersonating a real company, then requires the installation of specific software or the execution of code from GitHub during the technical interview. In this process, malware infiltrates the device and steals crypto wallet information.
How can I tell if I have been infected?
If unknown processes are running in the background after an interview, or if wallet funds move without warning, you should suspect an intrusion. The fastest verification is to check EDR logs alongside your wallet transaction history.
How is the cryptocurrency transferred to North Korea?
Stolen wallets are laundered through mixing services, cashed out at exchanges, or converted through P2P transactions. The funds then bypass the international financial network and flow into the North Korean regime—a pattern that has been repeatedly reported.
The WaterPlum case reconfirms that cyberattacks are no longer just a matter of technical vulnerabilities. By infiltrating a normal business process such as hiring and interviewing, this method demonstrates that “the moment you stop suspecting people” is itself the greatest vulnerability.
Both individuals and organizations can preemptively block a significant portion of this attack by adding a single verification step to their hiring process. The full advisory content is available in the initial Boan News report.
Source Material
This article was prepared after reviewing the following source: Boan News — Fake interviews aimed at crypto wallets… North Korea’s WaterPlum infects 30,000 devices across 100 countries
Expert Commentary (AI)
Information Security Threat Analyst
The most sophisticated case of social engineering stealing code execution privileges—a turning point that moves the defensive line from ‘device’ to ‘process’
Infiltration through fake job interviews is an expansion of the methods the Lazarus family has demonstrated, and the technical interview context effectively neutralizes anomaly detection of code execution requests, making the design highly efficient. The eight-month long campaign and the scale of 30,000 devices suggest an organization that has already built automated infrastructure (fake job posting generation, interview scheduling, malicious build distribution). The strength lies in the trust transfer structure. By leveraging legitimate hiring platforms and the names of real companies, victims do not even recognize that they have provided an attack surface. From a weakness perspective, threat actors still depend on exchanges and mixing services for final cash-out, so on-chain analysis and exchange cooperation remain the most realistic points of deterrence. The remediation point is cultural and tool-level: enforcing sandboxed execution of unverified external repository code as a default for developer workflows (Ephemeral VMs, devcontainer policies). This incident reconfirms that the very existence of seed phrases and wallet keys in digital storage is risky design. Looking ahead, adoption of publisher domain verification features on hiring platforms is likely to accelerate to prevent abuse of the reputation of legitimate platforms.
Crypto Asset Security Expert
The theft of 7,000 wallets is a collective failure of private key management—the fundamental vulnerability exposed by a hot-wallet-centric industry structure
The essence of this case is not the hacking technique itself, but the structural vulnerability of asset management in which private keys resided on interview devices—a low-trust environment. Beyond individual wallet owners, across the developer community, deployment signing keys and treasury wallet keys frequently coexist on the same device, creating structural risk in which infection damage can extend beyond wallet theft to smart contract signing authority. A point in favor is that the damage is distributed across a wide range of small wallets, which reduces individual investigative accessibility—advantageous to the perpetrators—but conversely makes it harder to conceal the fund aggregation path (mixing → cash-out). The weakness is that the industry overall implicitly encourages users to back up seed phrases digitally through UX design, and multisig and cold/hot separation remain advanced features applied only to expert accounts. Remediation points include strengthening hardware confirmation steps in wallet clients during transaction signing, and default-blocking large token approvals on new sessions. Looking ahead, this advisory is expected to reinforce the international coordination trend, accelerating more coordinated pushes for exchange KYC strengthening and mixing service regulation.
Critical Analyst
A handful of figures placed on the stage of a four-country joint advisory—and who benefits from those figures
The officially stated reason for the simultaneous four-country advisory is the ‘limitations of fund tracing,’ but a more accurate reading is that it signals each country has secured a substantial body of evidence. The fact that figures such as 30,000 devices, 7,000 wallets, and 1.7 billion yen were released all at once after eight months of infiltration shows how well the ‘North Korean threat’ narrative aligns with the timing of diplomatic, sanctions, and budget decisions—rather than the precise infection paths and detection dates. What we should truly pay attention to is who stands to benefit most from this advisory, apart from the victims. Hiring platforms can strengthen their revenue models by expanding publisher verification features, and international sanctions bodies can leverage this incident as justification for expanding mixing service regulation. Of course, this does not mean the incident itself is fabricated—the fact that North Korea-linked attacks are in continuous operation is cross-verified by multiple independent reports. However, the official narrative still leaves unexplained why the same pattern of tactics—requests to install corporate products—has not been completely blocked for years, and that gap is precisely what should be questioned. Finally, we should ask again whether the timing of the advisory, after eight months had passed, was tailored to align with certain sanctions or budget procedures rather than purely defensive purposes.
Underlying Scenarios
- There is a possibility that the fake interview campaign was actually a ‘Crown Jewel’ attack that an international coordination body had been observing for a significant period after already gaining substantial infrastructure access. If so, the eight-month period of passive observation may have been intentional, aimed at full infrastructure mapping and sanctions evidence gathering.
- The basis for calculating the 1.7 billion yen outflow is unclear regarding whether it reflects price changes between the time of theft and the time of cash-out. There is room for the figure to have been reported at a ‘sufficiently large’ size aligned with the timing of a particular sanctions resolution vote.
Leave a Reply