Full Report
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.
Analysis Summary
# Threat Actor: WaterPlum
## Attribution & Identity
* **Primary Name:** WaterPlum
* **Aliases:** Contagious Interview
* **Affiliation:** North Korea (DPRK). Specifically attributed to the **313 General Bureau of the Munitions Industry Department**, which is subordinate to the Central Committee of the Workers Party of Korea.
* **Associated Groups:** Strongly linked to and overlapping with **North Korean IT workers** operating overseas.
## Activity Summary
WaterPlum has conducted large-scale global campaigns targeting job seekers, specifically software developers and IT professionals. By posing as recruiters or employers from high-tech firms, they have infected more than **30,000 devices** across more than 100 countries. These operations serve a dual purpose: stealing sensitive data and exfiltrating cryptocurrency to fund the North Korean regime. Recent investigations led to the dismantling of a "laptop farm" in Japan used to facilitate these activities.
## Tactics, Techniques & Procedures
* **Social Engineering:** Impersonating legitimate companies in the AI, cryptocurrency, and NFT sectors to approach victims with "attractive job opportunities."
* **Malicious Interviews:** Using the pretext of a technical interview or coding assignment to deliver malware.
* **Infrastructure Facilitation:** Utilizing "laptop farms" (managed by local enablers in countries like Japan and the U.S.) to mask their true location and access corporate networks.
* **Employment Fraud:** Operating as functional IT workers (web system design and development) to gain legitimate access to client systems.
* **Financial Exfiltration:** Targeting and draining cryptocurrency wallets.
* **Shared Infrastructure:** Use of common IP addresses across laptop farms, cloud-sourcing services, and job applications.
## Targeting
* **Sectors:** Artificial Intelligence (AI), Cryptocurrency, Non-Fungible Tokens (NFT), Software Development, and Information Technology.
* **Geography:** Global (100+ countries), with specific emphasis on Japan, the United States, and Europe.
* **Victims:** Individual software developers, IT professionals, and Japanese cryptocurrency exchanges. Over 7,000 crypto wallets have been compromised.
## Tools & Infrastructure
* **Malware:** Specific malware families were not named in the article, but are delivered via job-related lures.
* **Infrastructure:**
* **Laptop Farms:** Geographically distributed hardware used to bypass geo-fencing and provide a "local" presence for remote workers.
* **Cloud-sourcing services:** Used for operational agility and anonymity.
* **IP Addresses:** [Redacted/Defanged] – The report notes shared IP usage between WaterPlum actors and IT workers.
## Implications
WaterPlum represents a sophisticated fusion of traditional cybercrime (theft) and state-sponsored espionage/sanction evasion. By embedding themselves into the global supply chain as "remote workers," they gain persistent, legitimate-looking access to sensitive corporate environments. The successful theft of $11 million in cryptocurrency highlights their role as a primary revenue generator for the North Korean government, while their vast infection footprint (30,000+ devices) creates a massive platform for potential future intelligence operations.
## Mitigations
* **Verification:** Rigorously verify the identity of prospective recruiters and employers via secondary, out-of-band communication channels.
* **Technical Screening Safety:** Exercise extreme caution when asked to download software, clone repositories, or run code for "technical assessments" from unverified sources. Use sandboxed environments for such tasks.
* **Internal Hiring Controls:** Implement strict background checks and identity verification for remote IT contractors to identify potential North Korean IT worker personas.
* **Network Monitoring:** Monitor for unauthorized remote access tools and unusual login patterns associated with laptop farms or suspicious VPS/Cloud provider IPs.
* **Wallet Security:** Use hardware wallets and multi-signature approvals for organizational cryptocurrency assets.