North Korea-linked hackers infected over 30,000 devices and stole sensitive data from more than 7,000 cryptocurrency wallets in a global cyber attack, Japanese law enforcement and the FBI confirmed. Targets spanned more than 100 countries, with the coordinated attacks occurring between December 2025 and July 2026.
WaterPlum’s global operation targets crypto professionals
The group known as WaterPlum, also referred to as Contagious Interview, systematically contacted IT professionals, particularly developers and other tech industry workers, by posing as legitimate employers offering attractive job opportunities. They primarily targeted individuals involved in blockchain, Web3, and cryptocurrency development.
According to the Japanese National Police Agency (NPA), attackers approached potential victims through social media, online job platforms, freelance sites, and gig-work portals. They often impersonated cryptocurrency, artificial intelligence, and NFT companies, as well as recruitment agencies, to establish credibility.
Authorities highlighted that the attackers asked job seekers to complete technical tasks or participate in coding interviews. These assignments required the download and execution of malicious files, which compromised devices and led to large-scale data theft.
These contaminated files were hosted on popular development and code-sharing platforms. Once downloaded as part of an interview or troubleshooting assignment, the malware embedded itself in the victim’s operating environment.
WaterPlum used a range of malware families in this campaign, including BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle. These malicious tools enabled unauthorized remote access, password and data extraction, keylogging, screenshot capture, and the collection of clipboard contents.
Investigators found that cyber criminals specifically targeted crypto wallet information, obtaining private keys, seed phrases, and other sensitive wallet credentials. The operation resulted in the theft of at least $10.71 million in cryptocurrency assets, with proceeds sent to wallets controlled by WaterPlum. The NPA estimated these assets to be worth roughly ¥1.7 billion.
Mini dictionary: WaterPlum, an advanced cybercrime group linked to North Korea, is known for sophisticated social engineering attacks focused on cryptocurrency and IT professionals.
| Metric | Value |
|---|---|
| Devices infected | 30,000+ |
| Crypto wallets targeted | 7,000+ |
| Countries affected | 100+ |
| Cryptocurrency stolen | $10.71 million |
The main victims were web designers, engineers, and blockchain professionals from across the globe. The scale and targeting indicate a strategic effort to acquire digital assets and credentials from highly specialized, high-value targets.
North Korean IT workers and laptop farm networks
Further investigation revealed that North Korean IT professionals, supported by local collaborators, remotely operated computers from third-party residences. These setups, labeled as “laptop farms” by Japanese authorities, allowed attackers to obscure their locations and identities.
Some of these workers accessed job and crowdsourcing sites using virtual private servers, operating from North Korea and regions including China, Russia, Africa, and Southeast Asia. Authorities also connected a suspicious engineering job application at the Japanese crypto exchange bitFlyer to these operations. The applicant used stolen identity data, VPN services, and refused relocation to Japan, insisting on payment in cryptocurrencies. Interviewers noted unexplained interruptions and multiple voices in the background, raising further suspicion.
Analysts discovered that IP addresses associated with the WaterPlum group were also found in connection to the bitFlyer application. This technical overlap suggested direct ties between the malware operation and the employment scam attempts.
Law enforcement suspects that WaterPlum and other North Korean IT operations remain linked to Bureau 313, a division under the North Korean Workers’ Party Central Committee. Bureau 313 is frequently cited in relation to the country’s state-sponsored cyber activities.
Mini dictionary: Bureau 313, a unit of North Korea’s Workers’ Party, is believed to manage cyber-operations for foreign currency acquisition via hacking and online fraud.
In response, Japanese authorities and the FBI recommended that software developers avoid running unfamiliar code directly on primary work systems. They suggested developers use virtual machines or limited computing environments for handling new or untrusted code to limit the impact of potential breaches.




