North Korean Hackers infected more than 30,000 devices across over 100 countries and regions between December 2025 and July 2026, according to Japan’s National Police Agency (NPA) and international partners. The campaign stole information from more than 7,000 cryptocurrency wallets, while wallets controlled by WaterPlum received at least $10.71 million in crypto assets.


WaterPlum Used Fake Crypto Jobs to Steal Wallet Data in 2026
WaterPlum, also known as Contagious Interview, targeted software developers and IT professionals through social media, online job platforms and freelance marketplaces.
The group impersonated legitimate AI, cryptocurrency and NFT companies, presenting attractive recruitment opportunities to potential victims. Japan’s NPA and the FBI assess that WaterPlum and some North Korean IT workers operate under North Korea’s 313 General Bureau of the Munitions Industry.
The attack often began with a technical interview or coding assignment. Victims were instructed to download files or packages and use them to complete a task or troubleshoot software, allowing malicious code to enter their systems.
The authorities identified malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle in the campaign.
Also Read: US Court Backs Bybit to Trace $1.5B North Korea Hack
Over 7,000 Crypto Wallets Targeted by WaterPlum Malware
The malware was designed to collect sensitive information from infected computers, including browser credentials, screenshots, keystrokes, private keys and cryptocurrency wallet data.
Authorities said more than 7,000 wallet-related records had been stolen during the campaign. At least $10.71 million worth of crypto was also transferred to wallets controlled by WaterPlum, although the figure does not represent the full potential value of information stolen.
The campaign also creates risks beyond individual wallet theft. Stolen credentials can potentially give attackers access to an employer’s wider network, while compromised identity documents may be reused in impersonation schemes.
The NPA warned that targeted companies could face theft of sensitive information, intellectual property and additional network compromise.
North Korean IT Worker Schemes Add Wider Crypto Security Risks
Japan also identified its first domestic “laptop farm” linked to North Korean IT workers. Such setups allow workers operating remotely to control computers located at supporters’ homes, helping disguise their actual location while obtaining employment or completing outsourced work.
Investigators found that the workers had transferred crypto and other assets worth hundreds of millions of yen overseas.
The FBI has separately warned that North Korean IT workers can use stolen identities, remote-access tools and U.S.-based facilitators to obtain employment and access company systems.
The agency says these schemes can expose organizations to data theft, intellectual-property loss and network compromise. This expands the risk beyond direct wallet attacks, making recruitment and employee-access controls an important security concern for crypto companies.
The investigation also identified a suspected North Korean IT worker who applied for an engineering position at Japanese cryptocurrency exchange bitFlyer in May 2025.
The applicant allegedly used another person’s identity documents and several VPN services, but bitFlyer detected suspicious characteristics during its interview process and did not hire the applicant.
$2.02B in 2025 Shows Scale of North Korean Crypto Theft
The WaterPlum findings come amid a broader increase in North Korean cryptocurrency theft. Chainalysis estimated that DPRK-linked hackers stole at least $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year. That figure places the $10.71 million associated with WaterPlum’s controlled wallets in a much wider pattern of North Korean crypto-related cyber activity.


The latest case also highlights why crypto companies face risks during recruitment, not only through direct exchange or protocol attacks. Japan’s authorities recommend limiting access privileges, checking applicants’ identities and locations, and avoiding untrusted code during technical assessments.
For crypto developers, the findings show that a seemingly ordinary recruitment exercise can become an entry point for wallet and corporate-network compromise.
Also Read: Crypto Theft Crisis: North Korea Fuels State Revenue Machine 2026





Be the first to comment