
North Korea linked hacking group WaterPlum has compromised more than 30,000 devices across over 100 countries and regions, stealing information from more than 7,000 cryptocurrency wallets while targeting developers through fake recruitment campaigns.
Summary
- WaterPlum infected more than 30,000 devices across over 100 countries and regions and stole information from more than 7,000 crypto wallets.
- Japanese and U.S. authorities linked WaterPlum and some North Korean IT workers to Bureau 313 of the Workers’ Party of Korea.
- Attackers posed as crypto, AI and NFT companies to target developers with malicious files disguised as interview tasks and coding tests.
- Japanese investigators dismantled a domestic laptop farm used by North Korean IT workers to remotely take jobs while concealing their locations.
- A suspected North Korean IT worker separately applied for an engineering role at bitFlyer in 2025 but was identified before being hired.
Japan’s National Police Agency said on Sept. 18 that its investigation, conducted with the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center and agencies in Australia and Germany, uncovered the group’s attack methods and links to North Korean IT workers.
Japanese and U.S. authorities assessed that WaterPlum, which is associated with the threat activity commonly known as Contagious Interview, and some North Korean IT workers operate under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department.
Investigators found that more than 30,000 computers were likely infected between around December 2025 and July 2026. The victims were spread across more than 100 countries and regions, including Japan, with web designers, engineers and people working in crypto, blockchain and Web3 among the main targets.
More than 7,000 cryptocurrency wallet records were stolen during the infections, while wallets controlled by WaterPlum received at least 1.7 billion yen, equivalent to roughly $10.7 million based on the exchange rate used by Japanese authorities.
Japan’s Foreign Ministry separately confirmed that authorities from Japan, the United States, Australia and Germany had jointly disclosed WaterPlum’s tactics and the activities of North Korean IT workers involved in foreign currency generation and recruitment schemes.
WaterPlum used fake crypto jobs to spread malware
WaterPlum approached software developers and other IT workers through social media, online job sites, gig platforms and freelance marketplaces, according to the Japanese police report. The attackers posed as legitimate artificial intelligence, cryptocurrency and NFT companies or recruitment services before presenting candidates with apparently attractive job opportunities.
During technical interviews or coding tests, candidates were instructed to download malicious programs hosted on collaborative development platforms and code repositories. Some victims were told that the files were needed to diagnose problems with video conferencing software or complete a coding assignment.
The group placed malware including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle inside malicious NPM packages. Once a device was compromised, attackers could establish backdoors and use remote access tools to retain access and move through affected systems. Information stealing malware was then used to extract confidential data and cryptocurrency.
Stolen information included browser credentials, keystrokes, screenshots and clipboard data. Private keys and seed phrases for cryptocurrency wallets were among the targeted records, along with identity documents such as passports and driver’s licenses stored on affected computers or shared folders.
Security researchers have documented similar recruitment methods in the crypto industry. As crypto.news previously reported,North Korean linked developers had worked inside more than 40 DeFi projects over seven years, according to MetaMask developer and security researcher Taylor Monahan. Investigators described job postings, emails, LinkedIn messages, Zoom calls and interview processes as recurring routes used to approach targets.
North Korean IT workers used laptop farms in Japan
Japanese investigators said they dismantled the first known domestic “laptop farm” connected to North Korean IT workers in the country. Under the arrangement, a local facilitator kept computers at their residence while workers remotely controlled the machines from elsewhere.
Workers used identity documents supplied by people living in Japan to impersonate them while seeking contracts. In some cases, payments were directed into bank accounts controlled by facilitators, who then transferred the money onward. North Korean workers connected to the investigations sent cryptocurrency and other assets worth hundreds of millions of yen overseas, according to the agency.
Some workers operated from North Korea, while others were based in China or Russia, with smaller numbers located in Africa and Southeast Asia. Laptop farms and virtual private servers allowed them to disguise where the work was actually being performed while accepting jobs through domestic and overseas crowdsourcing services.
Comparable operations have been prosecuted in the United States. Two U.S. men received 18 month prison sentences in 2026 for helping North Korean workers remotely access company laptops, while the Justice Department said the schemes involved nearly 70 companies and generated more than $1.2 million. The sentences brought the number of laptop farm facilitators sentenced in the United States over a five month period to eight.
U.S. authorities have pursued the proceeds of the employment schemes through cryptocurrency forfeiture cases as well. A federal judge in September ordered the forfeiture of roughly $212,700 in USDC and USDT traced to payment addresses used by North Korean IT workers, part of a Justice Department effort involving more than $7.74 million in digital assets.
Prosecutors said the forfeited wallet had received around 158,123 USDC from at least 10 addresses used to pay workers and 54,574 USDT from at least four other payment addresses. Authorities alleged that workers concealed their identities and locations while taking overseas technology jobs before routing their earnings through cryptocurrency.
bitFlyer caught suspected North Korean applicant
Japan’s investigation identified a separate attempt by a suspected North Korean IT worker to secure an engineering position at cryptocurrency exchange bitFlyer in May 2025.
The applicant submitted a resume under another person’s identity directly through the exchange’s recruitment form and used Gmail as the contact address. Investigators said the person accessed the application system through VPN and proxy services including NETNUT Proxy, Astrill VPN and High Speed Rabbit Proxy.
During an online interview, the applicant claimed to be Malaysian and living in Finland. The resume listed extensive experience across programming languages, blockchain, cryptocurrency and cloud services, along with education at a European university and employment in several European and Asian cities.
The applicant could answer simple questions about the listed skills but gave abstract responses or avoided more detailed questions, according to the agency. Investigators noted repeated checks of another monitor during the interview, occasional voices in the background and interruptions to the video feed. The person resisted relocating to Japan and insisted on receiving salary in cryptocurrency. bitFlyer identified the suspicious behavior and did not hire the applicant, and no damage was reported.
A similar recruitment attempt had previously been detected at Kraken, where an applicant suspected of links to North Korea joined an interview using a name different from the one on the resume and appeared to receive real time assistance during the call. The exchange later connected the applicant’s email address with information previously flagged by industry partners.
Investigators tied WaterPlum activity to the same infrastructure
Japanese authorities found a technical connection between the WaterPlum attacks, the overseas worker operations and the attempted bitFlyer recruitment.
IP addresses used by WaterPlum attackers matched addresses used by North Korean IT workers to connect to laptop farms and crowdsourcing services, according to the National Police Agency. Investigators found that the suspected North Korean worker who applied for the bitFlyer engineering position had used matching infrastructure.
The National Police Agency and FBI assessed that Bureau 313 played a central role in both WaterPlum’s cyberattacks and some of the foreign currency earning operations carried out by North Korean IT workers.
Japanese authorities advised companies to verify applicants’ claimed locations, qualifications and contact information, particularly when candidates insist on remote work or cryptocurrency payments. Employers were urged to check technical skills during interviews and scrutinize cases where a candidate’s stated residence does not correspond with the location of the IP address used to submit an application.









