A suspected North Korean hacking group has been blamed for infecting 30,000 PCs across the globe in an effort to steal cryptocurrency from unsuspecting users. 

On Friday, the FBI issued an alert about “WaterPlum,” a hacking group allegedly from North Korea  that’s been “victimizing individual IT professionals in Japan, the United States, Europe, and other countries.”

“From around December 2025 through July 2026, WaterPlum exploited at least 30,000 PCs in over 100 countries (including Japan and the United States),” the alert says. “The primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies.”

The hackers were also able to hit over 7,000 cryptocurrency wallets, stealing the login credentials and looting at least $10.7 million in virtual funds.  The group has been spreading malware to IT job seekers by reaching out on social media and through online job platforms, and then pretending to be official job recruiters for AI and cryptocurrency firms. “These actors go after software developers and IT professionals with fake ‘dream job’ offers,” the FBI noted.

The North Koreans will then trick victims to install the malware under the guise of completing a computer coding test or troubleshooting an error in an online video call. Other cybersecurity vendors have been tracking the threat, and cataloging the various malware strains, which include BeaverTail, capable of targeting both Windows and macOS. 

how it works

(FBI)

“WaterPlum actors upload malicious Node Package Manager packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCand, or StoatWaffle malware and related variants,” the FBI added. The group will then use the malware for backdoor access into the victim’s computer, downloading additional malware to persist over the infected device and the victim’s internet network. 

The FBI joined with authorities in Japan, Germany and Australia to issue the advisory, claiming WaterPlum works under North Korea’s 313 General Bureau of the Munitions Industry Department, which has been linked to the country’s R&D for nuclear weapons, missiles and military equipment. Hence, the stolen funds will likely aid North Korea’s weapons programs.

Recommended by Our Editors


This Tweet is currently unavailable. It might be loading or has been removed.

In response, the alert is advising IT job seekers to avoid “executing code from untrusted third parties on your PC or machines handling cryptocurrency assets or personal data. Only run unknown code inside a sandbox or virtual machine, and verify no obfuscated or unreadable sections are present before execution.”

“If antivirus software detects an infection or you suspect compromise, immediately disconnect the impacted device from the internet to disable external communications,” the alert adds. WaterPlum has also been spotted using “Al face-swapping software” to impersonate job recruiters during online video interviews. 

In addition, the FBI connected WaterPlum to North Korea’s ongoing effort to use the country’s workers to apply for and obtain remote IT jobs at legitimate companies. “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” the agency said in urging companies to vet their job candidates.

About Our Expert

Michael Kan

Michael Kan

Principal Reporter

Experience

I’ve been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I’m currently based in San Francisco, but previously spent over five years in China, covering the country’s technology sector.

Since 2020, I’ve covered the launch and explosive growth of SpaceX’s Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I’ve combed through FCC filings for the latest news and driven to remote corners of California to test Starlink’s cellular service.

I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.

I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I’m now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I’m always eager to learn more, so please jump in the comments with feedback and send me tips.


Read Full Bio