Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

qz+11newsbnd.bund+1A joint advisory from seven law enforcement and intelligence agencies across four countries has formally linked a North Korean hacking group to the same government bureau that oversees Pyongyang's sprawling network of fraudulent remote IT workers. The disclosure arrives alongside a new report from New Zealand revealing that a North Korean operative infiltrated a local business by posing as an IT contractor.
The advisory, published September 18 by Germany's Federal Intelligence Service (BND), identifies the hacking group known as WaterPlum — or Contagious Interview in the cybersecurity industry — as operating under North Korea's 313 General Bureau, a unit subordinate to the Munitions Industry Department of the Workers' Party of Korea. The document carries signatures from the FBI, the U.S. Department of Defense Cyber Crime Center, Japan's National Police Agency, Australia's Cyber Security Centre, and Germany's BND and BfV.ic3+2
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries and stole funds or credentials from roughly 7,000 cryptocurrency wallets, according to The Record. The total haul was approximately 1.7 billion yen — about $10.7 million — routed back to Pyongyang, Quartz reported.qz+1
WaterPlum operatives posed as recruiters on job boards and freelance marketplaces, targeting software developers and blockchain specialists. Victims were asked to complete coding tests or fix supposed errors in video conferencing software; the files arrived loaded with malware families including BeaverTail, InvisibleFerret, and OtterCookie. Once installed, the software harvested browser passwords, keystrokes, wallet seed phrases, and scanned identity documents. Investigators also found the group used AI face-swapping tools during video calls.therecord+3
Authorities drew a direct line between WaterPlum and North Korea's broader IT worker fraud scheme, citing overlapping IP addresses between the two operations. Some WaterPlum operatives simultaneously performed legitimate freelance web development while running malware campaigns.qz
Separately, New Zealand's National Cyber Security Centre disclosed in its annual Cyber Threat Report 2026 that a North Korean operative posing as a remote IT contractor was unknowingly hired by a large New Zealand business. The worker used a fake identity and recruited a New Zealand citizen to receive and operate the company's laptop — a tactic consistent with so-called "laptop farm" schemes.1news
After the business grew suspicious and terminated the contract, the operative threatened to release commercially sensitive information unless paid. NCSC Deputy Director-General Catriona Robinson warned that "this kind of activity is subject to UN sanctions" and urged employers to interview staff face-to-face and require new hires to collect IT equipment in person.1news
The BND advisory noted that WaterPlum and North Korea's IT worker operations are "almost certainly intertwined" and likely share organizational oversight under the Munitions Industry Department. U.S. authorities have estimated the broader IT worker scheme generated $800 million in 2024 alone. Japan's National Police Agency said investigators had, for the first time, located and shut down a North Korean laptop farm on Japanese soil, with records showing hundreds of millions of yen moved out of the country.bnd.bund+2