Japan National Police Agency: North Korea's cyber attack organization WaterPlum launched a large-scale attack targeting IT technicians
According to a joint alert issued by the Japanese National Police Agency, FBI, ASD/ACSC, BND, and BfV, the North Korean-backed cyber attack organization "WaterPlum" (also known as Contagious Interview) targets job seekers by disguising itself as an AI, cryptocurrency, and NFT company to post fake job listings. This lures job seekers into downloading NPM packages containing malware such as BeaverTail, InvisibleFerret, and OtterCookie, which then steal cryptocurrency wallet information and confidential data.As of July 2026, the organization has infected over 30,000 devices in more than 100 countries and regions worldwide, stealing information from over 7,000 cryptocurrency wallets, with the wallets under its control receiving at least approximately 1.7 billion yen (about 10.71 million USD) in cryptocurrency. The Japanese National Police Agency has discovered and dismantled a "notebook farm" established by local "supporters" for the first time in the country, where North Korean IT laborers remotely control PCs within the supporters' residences to conduct business, with the related amount involved reaching several hundred million yen.The police and FBI assess that WaterPlum and some North Korean IT laborers are under the unified command of the 313 Bureau of the Ministry of Military Industry of the Workers' Party of Korea, with the profits directly flowing into North Korea's national funding pool. The police remind IT technicians and corporate issuers to remain vigilant and avoid executing third-party code in unverified environments.