An unprecedented international coalition of law enforcement and intelligence agencies—including the United States FBI, the US Department of Defense, Japan's National Police Agency, the Australian Signals Directorate (ASD), and German federal authorities—has issued an urgent advisory detailing the global reach of the North Korean cyber operation WaterPlum. According to forensic findings, the state-sponsored adversary has compromised and currently commands at least 30,000 endpoint computers across more than 100 countries.
The campaign, tracked across the cybersecurity ecosystem under monikers such as Contagious Interview and DevJob, circumvents network firewalls by deploying sophisticated Social Engineering. Operating through professional networking platforms including LinkedIn and GitHub, operatives pose as corporate talent acquisition specialists from prominent technology organizations.
Adversaries specifically targeted software engineers and DevOps personnel specializing in artificial intelligence, cryptocurrency, and decentralized Web3 applications. Under the premise of a mandatory technical evaluation or coding challenge, targets were instructed to clone a compromised repository or download an archive containing weaponized dependencies. Upon execution, the payload initiates process-hollowing procedures, harvesting browser sessions, credentials, and local private keys.
Investigative findings confirm that the operation serves as a direct state-revenue generation mechanism. The threat actors compromised more than 7,000 individual cryptocurrency wallets, siphoning approximately 1.7 billion Japanese yen (roughly $10.7 million USD). The exfiltrated assets were systematically routed through decentralized mixers and cross-chain bridges to fund North Korea's prohibited ballistic missile development.
Concurrently, intelligence agencies warned that North Korean cyber operatives increasingly leverage stolen Western identities to secure legitimate remote development contracts, granting them native access to enterprise source code.
Actionable Guidance for IT and Security Teams
- Mandate Isolated Sandboxes for Coding Assessments: Strictly prohibit developers from executing interview coding tasks or unvetted scripts directly on corporate endpoints. Require isolated virtual machines.
- Inspect Dependency Trees in External Projects: Implement automated scanning for npm, PyPI, and RubyGem packages embedded within candidate test repositories before running builds.
- Enforce Hardware-Enforced Custody for Crypto Assets: Organizations managing digital assets must mandate multi-signature hardware security modules (HSM) requiring offline physical authorization.
- Strengthen Identity Verification for Remote Workers: Implement multi-step biometric verification and identity document validation during all remote onboarding workflows.
Evidence Status
- Confirmed: Joint cybersecurity advisory formally released by the FBI, DoD, NPA (Japan), ASD (Australia), and German law enforcement.
- Reported: In-depth technical telemetry and indicators of compromise (IoCs) validated by The Record and BleepingComputer.
- Unconfirmed: Precise organizational division of labor between WaterPlum, Lazarus Group, and Kimsuky under North Korea's Reconnaissance General Bureau (RGB) remains under intelligence review.
In Brief
- North Korean operation WaterPlum infected over 30,000 computers globally via weaponized job interview challenges.
- Intruders plundered 7,000 cryptocurrency wallets, exfiltrating over $10.7 million to state-aligned coffers.
- Organizations must sandbox coding tests and mandate hardware custody for digital assets.