Law enforcement agencies from Australia, Germany, Japan and the United States say North Korean operatives posed as recruiters to infect more than 30,000 devices and steal at least $10.71 million in cryptocurrency. The joint advisory, updated Thursday, tracks the activity under the name WaterPlum and ties it to a campaign that ran from December 2025 through July 2026.
The agencies said attackers compromised more than 7,000 cryptocurrency wallets in the process. Stolen funds were funneled back to Pyongyang, where they support the regime and, according to the advisory, its weapons programs. The four governments issued the update jointly after months of parallel investigations into the same infrastructure, and the coordinated release itself is unusual for advisories of this type.
How the scam works
The scheme targets web designers, engineers and cryptocurrency and Web3 specialists with bogus recruitment approaches. Victims are drawn into what looks like a normal hiring process, complete with interviews, take-home tasks and job offers. At some point the candidate is asked to complete a coding test or download what is described as project software, and that step is where the malware enters.
Security researchers have documented malicious npm packages spreading through the same campaign, alongside a fake Go DNS scanner distributed through more than 200 GitHub repositories. Once installed, the malware harvests credentials, cryptocurrency keys and sensitive data, and plants persistent remote access tools on the machine. That persistence matters: infected devices can be revisited months later, long after the victim has forgotten the interview that started it all.
The operation is linked to North Korea’s 313 General Bureau, the unit behind much of the country’s crypto theft infrastructure. Researchers note the group also impersonates victims to obtain jobs at Western companies, extending the campaign from simple theft into espionage and longer-term access to corporate systems.
The numbers behind the advisory
The $10.71 million figure, about 1.7 billion Japanese yen, covers thefts attributed to these tactics. It does not include the separate, larger revenue stream from North Korean IT workers placed inside foreign companies under stolen identities, which the same advisory documents in parallel.
| WaterPlum campaign, per joint advisory | Figure |
|---|---|
| Devices infected | 30,000+ across 100+ countries |
| Crypto wallets compromised | 7,000+ |
| Funds stolen | $10.71 million |
| Active period | December 2025 to July 2026 |
| Attribution | North Korea’s 313 General Bureau |
“Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency,” the advisory said. “Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims’ employers, clients, or contracting parties.” The agencies added that stolen sensitive information can also be used for extortion, giving the operation a second monetization path beyond the wallet thefts.
Warning signs for employers
The agencies listed a set of red flags for companies hiring remote technical staff. Applicants may submit impressive resumes claiming prestigious education and work experience that does not hold up in an interview. They may refuse to meet in person, suffer suspicious interruptions to video feeds, or have voices audible in the background of calls.
Requests for payment in cryptocurrency are another marker. So is the use of AI face-swapping software during video calls, which produces visual artifacts and often leads the applicant to disable their camera shortly after the call begins. None of these signals is conclusive on its own, but in combination they have proven reliable enough for the agencies to publish them as formal guidance to employers and staffing firms.
A familiar playbook, inverted
The recruiter campaign complements North Korea’s better-known tactic of placing its own IT workers in technology roles at Western and allied companies. That scheme has generated revenue for the regime for years and has been extensively documented by the US State Department and private security firms. Companies that caught one fraudulent worker often discovered several more already inside, hired through the same staffing intermediaries.
What makes WaterPlum notable is the inversion: instead of North Koreans applying for jobs, the regime’s operatives pose as the employers. The fake openings appear at crypto, AI and NFT companies, precisely the sectors where staff hold wallet keys, exchange credentials and production access on their laptops. A single infected developer machine can expose custody infrastructure worth far more than the average theft recorded in the advisory.
The geographic spread also stands out. Devices were infected in more than 100 countries, which suggests the campaign was not aimed at any single exchange or market. Anyone with a public portfolio and a wallet was a candidate target, and the low cost per attempt made volume the strategy.
What companies can do
The advisory’s practical guidance is unglamorous. Treat recruitment pipelines as an attack surface: coding tests, onboarding packages and interview software all need the same scrutiny given to any third-party code that touches employee machines. Sandbox take-home evaluations rather than running them on staff laptops. Verify recruiter identities through independent channels before sharing anything sensitive, and require hardware keys for any account that can move funds.
For individuals, the advice is blunter. A real employer does not need you to disable antivirus software to run a coding test, and a real recruiter does not send proprietary build tools as a first contact. The agencies asked victims and companies to report incidents to national authorities so the stolen-funds tracing can continue across the four jurisdictions.
The advisory did not announce arrests or sanctions tied specifically to WaterPlum. Given the sums involved, further designations are considered likely by analysts tracking the file, but nothing was confirmed in the document itself. The campaign’s shutdown in July, as reconstructed by the agencies, does not mean the infrastructure is gone; the same operators have rebranded before.
