MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-19 · via BleepingComputer

Global probe ties North Korean group to mass device compromise and crypto theft

Image via BleepingComputer
Image via BleepingComputer

A joint advisory from Japanese, US, Australian, and German authorities attributes a campaign that infected at least 30,000 devices across over 100 countries to the North Korean hacking group WaterPlum. The operation, linked to the 'Contagious Interview' scheme, used fake job offers and malicious packages to steal credentials and cryptocurrency, transferring over $10.7 million to North Korea. The advisory details multiple malware families and warns of potential network pivoting for espionage.

Expanded Detail

The advisory identifies a sophisticated social engineering pipeline, where fake recruitment processes on freelance platforms deliver malicious code disguised as legitimate technical tasks. WaterPlum operators reportedly use AI face-swapping during video interviews before disabling cameras, while some operatives simultaneously work as remote IT contractors, blurring lines between espionage and fraud. Investigators also uncovered a "laptop farm" in Japan, suggesting infrastructure for laundering stolen identities and funds.

The campaign's reach spans over 100 countries, with attackers pivoting from credential theft to corporate network infiltration. By reusing stolen identity documents for fraudulent employment, the group extends its operational lifespan beyond initial compromises, creating persistent access to victim networks and enabling long-term intelligence gathering alongside financial theft.

Context

This campaign could significantly undermine trust in remote hiring practices, particularly in tech sectors where coding assessments are standard. Job seekers may become wary of legitimate opportunities, while companies face increased screening costs and liability. The theft of credentials and cryptocurrency directly harms individuals, but the network pivoting threat could expose corporate intellectual property, affecting broader economic security. The scale—30,000 devices—suggests this may represent a systemic vulnerability in global digital recruitment, potentially reshaping how organizations verify remote workers and handle sensitive data.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Compromised HBO Max Reddit account used to spread info-stealing malware via fake ads · Cybersecurity
ClickFix malware scheme spreads through compromised Reddit ads · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “North Korean WaterPlum hackers infected 30,000 devices worldwide.” Browse more stories.