Famous Chollima/ WaterPlum Cyber Actor Group Continue Targeting IT Professionals

Executive Summary

A joint law enforcement advisory conducted by the National Police Agency of Japan (NPA),  National Cybersecurity Office of Japan (NCO), US Federal Bureau of Investigation (FBI), US Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Germany Federal Intelligence Service (BND), and Germany Federal Office for the Protection of the Constitution (BfV)  warns that the North Korean hacking group WaterPlum, also known as Famous Chollima and linked to the campaign Contagious Interview, compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than 10.7 million USD in stolen cryptocurrency to North Korea. Detailed in a report published 18 September 2026, WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities. They often impersonate legitimate artificial intelligence, cryptocurrency, or non-fungible token companies and have also used recruiting services. The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.

Key Takeaways

  • WaterPlum actors recruit job seekers internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces. During interviews, WaterPlum actors instruct job seekers to download and execute malicious files, hosted on multiple online collaboration software developer platforms and code repositories.
  • Once WaterPlum actors obtain backdoor access to victim computer networks through malicious loader downloads, they use Remote-Access Trojans to preserve connectivity, persistence, and pathways to pivot across victim systems. The actors use infostealers to exfiltrate the victims sensitive data and cryptocurrency to a Command-and-Control IP address for remote management of infected devices or networks.
  • Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments. Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency.
  • Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients. WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange.
  • For the first time in Japan, authorities successfully identified, investigated, and dismantled a laptop farm operated by an enabler in Japan. Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan.

More Recent Blog Posts

Executive Summary An Infoblox cybersecurity report, published on 15 September 2026, has revealed that online casinos are being used to disguise and deploy...

Executive Summary Manchester Airports Group has disclosed on 27 August 2026 that an unauthorized third party accessed customer data belonging to approximately 8.7 million people...

Cyberattacks are relentless, with thousands occurring every day. Yet despite billions spent on defense, breaches persist, leaving organizations reeling from financial and reputational...