Police and intelligence agencies across Japan, the US, Australia, and Germany reported that a North Korean-linked group stole funds or credentials from over 7,000 cryptocurrency wallets worldwide. Investigators stated that approximately ¥1.7 billion, or $10.71 million, was transferred to North Korea over a seven-month campaign ending in July 2026.
International cybercrime operation exposed
The group, known as WaterPlum by Japan’s National Police Agency (NPA) and referred to as Contagious Interview within the cybersecurity industry, infected at least 30,000 devices in over 100 countries. Authorities noted that targets included web designers, engineers, and professionals in crypto, blockchain, and Web3 development.
A joint advisory documenting the operation was signed by Japan’s NPA and National Cybersecurity Office, the US Federal Bureau of Investigation and Department of Defense Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre, and Germany’s BND foreign intelligence service alongside domestic security agency BfV.
Japan’s NPA and the FBI assessed that WaterPlum operates under the 313 General Bureau of North Korea’s Munitions Industry Department, which falls under the central committee of the country’s ruling Workers’ Party. Both WaterPlum and North Korea’s remote IT workers reportedly used overlapping IP addresses to access “laptop farms”, crowdsourcing services, and job applications.
Authorities connected these activities to a coordinated operation, supporting the theory that WaterPlum and the remote IT worker deployments are part of a single effort managed by the regime.
Malware and social engineering tactics
Security officials said the attackers impersonated companies in AI, crypto, or NFT sectors, approaching software developers through social media, job boards, and freelance platforms. Developers were then asked to download files, presented either as coding assessments or technical troubleshooting tasks, which concealed malware.
The advisory named five malware types, including BeaverTail, InvisibleFerret, and StoatWaffle—the latter often found hiding in blockchain-themed software repositories.
Mini dictionary: Laptop farm, a domestic or residential location equipped with multiple computers, operated remotely by external actors—often used by clandestine workers or hackers to mask identities and diversify attack vectors.
Further investigation revealed additional social engineering tactics. Members of the group used AI-powered face-swapping tools for video interviews, later turning off their cameras and requesting the other party do the same, allegedly due to “connection issues.” They also used text-to-speech tools to perfect Japanese pronunciation and worked exclusively on free machine-translation and AI services. Surveillance revealed that during holidays in North Korea, the operatives stopped work to play games and watch soccer videos.
Authorities observed the attackers relied on AI face-swapping and text-to-speech tools during interviews, practiced Japanese pronunciation with machine translation services, and exploited developer platforms to spread malware in coding assignments.
In a significant move, Japanese police dismantled a domestic laptop farm for the first time, finding hundreds of millions of yen had been moved abroad in crypto. Such setups typically involve an enabler’s home where computers are remotely operated by North Korean, Chinese, or Russian IT workers.
Rising trend in North Korean crypto thefts
CertiK, a blockchain security firm, reported that the incident forms part of a broader campaign. In 2025, groups linked to North Korea were responsible for $2.06 billion in crypto thefts, approximately 60% of the market’s total reported losses from hacks. An attack on Drift Protocol in April 2025 alone netted $285 million, following a prolonged infiltration in which hackers posed as representatives of a trading firm.
Japan’s crypto sector has also increased vigilance. A local exchange rejected a May 2025 job applicant whose suspicious résumé and language inconsistencies suggested the application was linked to North Korean operations. Industry experts noted patterns, including requests to be paid in crypto, reluctance for in-person meetings, and repeated glances at secondary computer screens, as red flags of potential fraud.
| Group/Incident | Stolen Amount | Year/Period | Responsible Party |
|---|---|---|---|
| WaterPlum/Contagious Interview | $10.71 million | Dec 2025 – Jul 2026 | North Korean group |
| All North Korea-linked thefts | $2.06 billion | 2025 | Multiple North Korean groups |
| Drift Protocol hack | $285 million | April 2025 | North Korea-linked attackers |
International cybersecurity cooperation is ongoing, with law enforcement and exchange operators reporting increased efforts to identify and prevent similar incidents in the rapidly evolving crypto landscape.




