Live Feeds
● LIVE Updated 1h ago · 19 sources tracked

North Korean WaterPlum hackers infected 30,000 devices worldwide

North Korean hackers linked to the WaterPlum group have compromised 30,000 devices worldwide through fraudulent job interviews and coding tests targeting IT developers, including Rust team members and crate owners. The campaign drained up to $11 million from cryptocurrency wallets, taking funds or credentials from 7,000 wallets across 100 countries including Japan. The FBI and Japanese police have issued joint warnings about the operation, while Japanese authorities dismantled a North Korean laptop farm as part of an international law enforcement response involving the US, Germany, and Australia.

🎙️

Listen to Live Briefing

Real-time synthesized voice briefing · Live Feeds Desk

⏱ ~3 min
Speed:
RSS Source map (19)
Key Developments & Real-Time Context
Text size:
  • North Korean WaterPlum hackers infected 30,000 devices worldwide.
  • The WaterPlum group looted $10.7 million in cryptocurrency and planted persistent RATs.
  • The campaign targeted IT developers, including Rust team members and popular crate owners, via video calls.
  • The FBI and Japanese police issued warnings about North Korea-linked WaterPlum hackers targeting IT developers.
🛡️ Source Corroboration: 19 independent reporting domains (95% confidence) ⏱ Read time: ~2 min

What changed

Japan dismantled its first North Korean laptop farm while international allies detailed the broader WaterPlum campaign.

Live updates

  1. North Korean Hackers Infect 30,000 Devices in Job Scam

    North Korean hackers linked to the WaterPlum group have compromised 30,000 devices worldwide through fraudulent job interviews and coding tests targeting IT developers, including Rust team members and crate owners. The campaign drained up to $11 million from cryptocurrency wallets, taking funds or credentials from 7,000 wallets across 100 countries including Japan. The FBI and Japanese police have issued joint warnings about the operation, while Japanese authorities dismantled a North Korean laptop farm as part of an international law enforcement response involving the US, Germany, and Australia.

    Why it matters

    The operation relies on social engineering tactics where attackers pose as recruiters to trick technology professionals into video calls and technical assessments. Once engaged, the malicious actors deploy persistent remote access trojans and malware payloads during coding tests. This methodology highlights a growing trend of human infiltration and targeted supply chain attacks against software developers to harvest valuable digital assets.

    What is confirmed

    • North Korean WaterPlum hackers infected 30,000 devices worldwide.
    • The WaterPlum group looted $10.7 million in cryptocurrency and planted persistent RATs.
    • The campaign targeted IT developers, including Rust team members and popular crate owners, via video calls.
    • The FBI and Japanese police issued warnings about North Korea-linked WaterPlum hackers targeting IT developers.
    • Japan dismantled a North Korean laptop farm as part of a wider US, German, and Australian joint investigation.

    Still unconfirmed

    • Funds or credentials were taken from 7,000 crypto wallets.

    What to watch next

    • Further international arrests or enforcement actions against the WaterPlum infrastructure.
    • Additional disclosures from the FBI, Japanese police, or allied agencies regarding the stolen crypto funds.
    Sources used for this update (22)
    1. BleepingComputer — North Korean WaterPlum hackers infected 30,000 devices worldwide
    2. The Japan Times — North Korean hackers behind crypto thefts across 100 countries, including Japan
    3. The Register — North Korea's fake job interviews infected 30,000 devices
    4. Yahoo — Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets
    5. Binance — FBI and Japanese Police Warn of North Korea-Linked WaterPlum Hackers Targeting IT Developers
    6. inc.com — North Korean Hackers Posed as Recruiters. They Infected 30,000 Devices Worldwide
    7. CryptoRank — How Fake Job Offers Are Stealing Crypto Developers’ Wallet Data—and How to Spot Them
    8. Tom's Hardware — North Korea used job interviews to deploy malware on 30,000 devices during coding tests — WaterPlum group loots $10.7 million in crypto and plants persistent RATs
    9. Modern Tokyo Times — North Korea and Cyber Warfare (Lazarus Group and ByBit Hack – Lawsuit Filed)
    10. Barracuda Networks Blog — The fake worker threat and the rise of human infiltration
    11. 深潮TechFlow — Coding Interview = Stolen Wallet? North Korean Hacker Group WaterPlum’s Hiring Scam Exposed
    12. securityweek.com — Rust Team Members and Popular Crate Owners Targeted via Video Calls
    confidence 95%
📊

Community Sentiment: How do you assess this situation?

Voice your perspective · Real-time aggregated sentiment from the Live Feeds community