North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
North Korean hackers, operating under the ‘WaterPlum’ campaign, are targeting job seekers globally – particularly IT professionals – to steal cryptocurrency and facilitate their infiltration into tech companies and ultimately, funnel funds back to North Korea. The campaign has been ongoing since 2020 and involves sophisticated tactics like laptop farms and AI-powered identity manipulation. The FBI and law enforcement agencies are actively working to disrupt these operations.
North Korean hackers are engaging in a sophisticated and ongoing cyber campaign targeting job seekers across 100 countries, primarily focusing on IT professionals, to steal cryptocurrency and facilitate their entry into lucrative roles within tech companies. The campaign, known as ‘WaterPlum,’ has been active since 2020 and is linked to a broader effort to generate revenue for North Korea.
Job seekers are contacted through various channels, including social media platforms, gig work websites, and freelance portals, and are instructed to download files during the interview process. These files contain malware, including variants of BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, which allows the hackers to infect devices and steal cryptocurrency wallet credentials. The hackers also install infostealers and remote management tools to maintain access to victim devices, hoping to secure employment at other tech firms and subsequently gain access to corporate systems.
Japanese police recently disrupted a laptop farm operated by a Japanese national, discovering evidence of several hundred million Japanese yen being sent to addresses outside the country. The FBI has uncovered dozens of laptop farms across the U.S. used by North Koreans to simulate local work. These laptop farms are used to create a false impression of local employment, allowing North Korean IT workers to apply for positions at Japanese cryptocurrency companies.
North Korean IT workers are utilizing various techniques to enhance their chances of success, including AI face-swapping software, text-to-speech software with Japanese pronunciations, and AI translation tools. In one case, a North Korean IT worker used AI to mimic a Japanese accent during interviews. The campaign is deeply intertwined with the IT worker scheme, where North Koreans steal or purchase identities to secure employment in the U.S. or Europe.
According to the report, the WaterPlum campaign and several IT worker schemes are run through North Korea’s General Bureau of the Munitions Industry Department, a department within the Central Committee of the Workers Party of Korea. Previous investigations have revealed that multiple government departments within North Korea operate squads of cyber workers involved in revenue-generating activities, including legitimate IT work, cryptocurrency theft, and data extortion. For example, a North Korean IT worker previously extorted a company over payment and published its proprietary source code online, and another defaced a hiring company’s website, rendering it inaccessible.
