A North Korea-linked hacking group infected more than 30,000 devices and stole data from over 7,000 crypto wallets across more than 100 countries, Japan's National Police Agency says. The group, known as WaterPlum, used fake job offers to trick IT professionals into installing malware between December 2025 and July 2026.
Japan's National Police Agency says a North Korea-linked hacking group infected more than 30,000 devices and stole data from over 7,000 crypto wallets between December 2025 and July 2026. The attacks hit targets in more than 100 countries, with the FBI and other foreign agencies assisting the investigation.
WaterPlum Used Fake Job Offers to Target Developers
The group, also called Contagious Interview, primarily targeted IT professionals. It reached job seekers through social media, online job sites, freelance platforms, and gig-work sites, posing as cryptocurrency, artificial intelligence, and NFT companies as well as recruitment agencies.
Once in contact, targets were asked to complete coding tasks or technical interviews. These tasks led victims to download malicious files hosted on development platforms and code repositories. WaterPlum used several malware families in the campaign, including BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle, which could grant remote access, capture passwords and keystrokes, and log clipboard data.
Wallets Tied to the Group Received $10.71 Million
The malware also targeted wallet data directly, pulling private keys, seed phrases, and other sensitive wallet information from infected machines. Japan's National Police Agency found that wallets controlled by WaterPlum received at least $10.71 million in cryptocurrency, or about ¥1.7 billion. The primary victims were Web designers, engineers, blockchain workers, and Web3 professionals.
North Korean IT Workers Ran 'Laptop Farms'
Investigators also uncovered North Korean IT workers operating with local supporters, using remotely controlled computers based in the supporters' homes, arrangements Japanese authorities called "laptop farms" that let workers hide their true identities online. Investigators also found a suspected North Korean IT worker who applied for an engineering role at Japanese crypto exchange bitFlyer in May 2025 using someone else's identity and a VPN, then gave unclear technical answers despite claiming extensive experience, refused to relocate to Japan, and demanded a salary paid in cryptocurrency.
Matching IP addresses linked WaterPlum to the North Korean IT worker activity, including the bitFlyer application. The NPA and FBI believe both are connected to Bureau 313, part of North Korea's Workers' Party Central Committee.
Authorities are urging developers not to run unknown code on work computers, and to use virtual machines or limited environments for new projects.
Source: Live Bitcoin News
Trading involves risk.