North Korean WaterPlum Campaign Transfers $10.71 Million in Crypto
A sophisticated North Korean cyber campaign, codenamed WaterPlum, has been uncovered, transferring at least $10.71 million in cryptocurrency to the Democratic People's Republic of Korea (DPRK).
The operation targeted web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technology, compromising over 30,000 devices in more than 100 countries between December 2025 and July 2026.
The attackers posed as recruiters or employers, directing candidates to download files or run code during fake job interviews and coding assignments. Malicious software, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware, was used in the campaign.
Japan's National Police Agency (NPA) and the FBI assessed that WaterPlum and North Korean IT workers operated under the 313 General Bureau of the Munitions Industry Department, which reports to the Workers' Party of Korea's Central Committee. Japanese authorities also dismantled a domestic laptop farm used by North Korean IT workers.