Circuit Wire — a daily news update from the Circuit.
Police and intelligence agencies in four countries said on September 18 that a North Korean group known as WaterPlum infected at least 30,000 devices in more than 100 countries. The joint advisory came from Japan's National Police Agency and National Cybersecurity Office, the FBI and the US Department of Defense Cyber Crime Center, Australia's Cyber Security Centre, and Germany's BND and BfV.
The activity ran from around December 2025 through July 2026. Investigators say the group took funds or account credentials from more than 7,000 cryptocurrency wallets and transferred 1.7 billion yen, about $10.71 million, to North Korea. The agencies assess that WaterPlum operators and some North Korean IT workers sit under the 313 General Bureau of the Munitions Industry Department.
The approach starts at the hiring stage. Operators pose as prospective employers, often impersonating artificial intelligence, cryptocurrency or NFT companies, and approach developers through social media, job boards and freelance marketplaces. Candidates are asked to sit technical interviews or complete coding assignments, then told to download a project or fix a problem with the video call. Those files carry malware that the advisory names as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
Once inside, the operators harvest browser passwords, clipboard contents, keystrokes, screenshots and wallet seed phrases. They also collect ID images such as driver's licenses and passports, which North Korean IT workers then reuse to impersonate victims and win contracts. Access to a developer's machine can open a route into the networks of that person's employer or clients, which the advisory links to intellectual property theft and espionage.
The second strand concerns those IT workers directly. They operate through laptop farms, where an enabler hosts employment-issued computers at a residence and the worker controls them remotely from North Korea, China or Russia. Japanese authorities identified and dismantled such a farm for the first time, finding that several hundred million yen had moved abroad.
The advisory also lists what interviewers noticed. Applicants used AI face-swapping software on camera, then switched video off and blamed network problems. One Japanese cryptocurrency exchange received an application in May 2025 from a candidate whose résumé claimed a decade of skills across ten programming languages, yet whose English did not match the stated education and work history. The company did not hire him.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

