supply-chaintrade-pressNewsThe Broadside1 min read

Allies name WaterPlum as North Korea's fake-job crypto arm

The joint advisory collapses what were treated as separate problems (credential-theft malware and North Korean IT-worker infiltration) into a single operational picture, backed by shared IP addresses and laptop-farm evidence.


TL;DR

The FBI, DoD Cyber Crime Center, and allied agencies from Japan, Australia, and Germany issued a joint advisory tying the WaterPlum group (also tracked as Contagious Interview) to the 313 General Bureau. WaterPlum poses as AI, crypto, and NFT firms to lure software developers and IT professionals into installing malware. The group has infected more than 30,000 devices across 100-plus countries and moved the equivalent of nearly $11 million in cryptocurrency from over 7,000 wallets. For the first time, Japanese authorities dismantled a laptop farm used by the group's enablers.

The advisory is significant less for the attribution (North Korea's fake-job campaigns have been documented since at least 2020) than for the evidence it assembles. The agencies found WaterPlum operatives and North Korean IT workers using the same IP addresses to access laptop farms, cloud-sourcing services, and job applications at a Japanese cryptocurrency exchange. That's not circumstantial overlap; it's shared infrastructure.

The alert describes two faces of the same operation. One is credential theft and crypto draining through trojanized job-application software. The other is the better-known scheme where North Korean nationals get hired for remote IT roles, then funnel salaries and access back to the regime. The agencies treat these as a single problem now, which matters for anyone building a threat model that separates supply-chain infiltration from endpoint compromise.

What the enabler thread means

Japanese authorities said they identified, investigated, and dismantled a laptop farm (a physical array of machines routed through intermediary countries to make North Korean-originating traffic appear local) and obtained evidence that the operator had transferred several hundred million yen in cryptocurrency abroad. The FBI added that it continues to identify and prosecute U.S.-based enablers providing facilitation services to North Korean IT workers. That enforcement language has been present in prior advisories, but naming a successful takedown alongside an ongoing U.S. prosecution thread signals a shift from warning to action.

The advisory lands the same week the Multilateral Sanctions Monitoring Team released a report exposing thousands of North Korean nationals employed in industries worldwide. The timing isn't accidental.


Published ·Deep Fathom

Allies name WaterPlum as North Korea's fake-job crypto arm — The Broadside