A North Korea-linked hacking group known as WaterPlum has reportedly compromised more than 30,000 computers worldwide and stolen information connected to over 7,000 cryptocurrency wallets.
According to Japan’s National Police Agency, the attacks affected users across more than 100 countries and regions, with software developers, engineers, and people working in crypto, blockchain, and Web3 among the main targets.
Japanese and U.S. authorities have linked WaterPlum, which is associated with the cyber campaign commonly known as Contagious Interview, to Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department.
The campaign allegedly relied heavily on fake job opportunities, malicious coding tests, and fraudulent recruitment processes designed to trick victims into installing malware.
WaterPlum targeted developers through fake job offers
The hacking group reportedly approached developers and other technology workers through social media platforms, freelance websites, job boards, and online recruitment services.
Attackers often pretended to represent legitimate cryptocurrency, artificial intelligence, NFT, or technology companies.
Victims were then invited to complete technical interviews or coding assignments as part of what appeared to be a normal recruitment process.
During these interviews, candidates were asked to download programs, repositories, or project files that secretly contained malicious software.
In some cases, victims were told they needed to install the files to fix video-conferencing problems or complete coding tests.
Once installed, the malware could give attackers access to the victim’s computer and sensitive information.
More than 7,000 crypto wallet records were stolen
Japanese investigators said more than 30,000 computers were likely infected between around December 2025 and July 2026.
The infections spread across more than 100 countries and regions, including Japan.
Authorities said information connected to more than 7,000 cryptocurrency wallets was stolen during the campaign.
Wallets controlled by WaterPlum also received at least 1.7 billion yen, or roughly $10.7 million based on the exchange rate used by Japanese authorities.
The stolen data reportedly included browser credentials, screenshots, keystrokes, clipboard information, identity documents, and cryptocurrency wallet credentials.
Private keys and seed phrases were among the most sensitive information targeted by the attackers.
If criminals obtain a wallet’s private key or seed phrase, they may be able to gain control of the wallet and transfer its cryptocurrency.
Hackers used malicious NPM packages
WaterPlum reportedly distributed several types of malware through malicious NPM packages and other software files.
The malware families identified by investigators included BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Once a target’s device was infected, the attackers could install backdoors and remote-access tools.
These tools allowed the hackers to maintain access to compromised systems and collect additional information over time.
Information-stealing malware was then used to capture sensitive data such as passwords, cryptocurrency wallet information, identity documents, and other confidential files.
The use of coding repositories and software packages made the campaign especially dangerous for developers, who regularly download dependencies and project files as part of their work.
Crypto and Web3 developers were major targets
Developers working in cryptocurrency and Web3 were among the main groups targeted by the campaign.
These employees can have access to valuable digital assets, company infrastructure, private repositories, wallets, and blockchain systems.
Security researchers have previously warned that North Korean-linked workers and developers have attempted to enter crypto companies and decentralized finance projects through legitimate-looking employment opportunities.
Fake recruitment campaigns can therefore serve two purposes.
Attackers may attempt to infect applicants with malware, while suspected North Korean IT workers may also apply for legitimate technology positions using false identities.
Both approaches can potentially provide access to cryptocurrency companies and their internal systems.
Japan dismantled a North Korean-linked laptop farm
Japanese authorities also said they uncovered what they described as the country’s first known laptop farm linked to North Korean IT workers.
A laptop farm allows a remote worker to operate computers physically located in another country.
In the Japanese case, a local facilitator reportedly kept laptops at a residence while overseas workers remotely accessed the machines.
This setup made it appear that the workers were operating from Japan even when they were physically located elsewhere.
Authorities said some workers used identity documents belonging to people in Japan when applying for jobs.
Payments were sometimes sent to bank accounts controlled by facilitators before being transferred onward.
Investigators said workers connected to the schemes transferred cryptocurrency and other assets worth hundreds of millions of yen overseas.
Workers reportedly operated from several countries
Some suspected North Korean IT workers were believed to be operating directly from North Korea.
Others reportedly worked from locations in China and Russia, while smaller groups operated from Africa and Southeast Asia.
Laptop farms, VPN services, proxies, and virtual private servers helped workers hide their actual locations.
These tools allowed them to apply for remote jobs and freelance contracts while appearing to be located in countries accepted by employers.
Similar operations have also been uncovered in the United States.
U.S. authorities have prosecuted individuals accused of helping North Korean workers remotely access company laptops.
The Justice Department has also pursued cryptocurrency connected to such employment schemes.
Suspected North Korean worker applied to bitFlyer
Japanese investigators also identified an attempted recruitment case involving cryptocurrency exchange bitFlyer.
In May 2025, a suspected North Korean IT worker reportedly applied for an engineering position at the exchange while using another person’s identity.
The applicant submitted a resume directly through bitFlyer’s recruitment system and used VPN and proxy services to hide the real location of the connection.
During an online interview, the applicant claimed to be Malaysian and living in Finland.
The resume reportedly included extensive experience in blockchain, cryptocurrency, cloud computing, and multiple programming languages.
However, investigators said the applicant struggled with more detailed technical questions despite being able to answer basic ones.
Interviewers also noticed repeated glances toward another monitor, voices in the background, and interruptions in the video feed.
The applicant reportedly resisted relocating to Japan and requested salary payments in cryptocurrency.
bitFlyer identified the suspicious activity and did not hire the applicant.
Authorities said no damage was reported.
Authorities found links between hacking and recruitment activity
Japanese investigators said they discovered infrastructure connecting WaterPlum’s hacking operations with suspected North Korean IT worker activity.
IP addresses used during WaterPlum attacks reportedly matched addresses used by suspected North Korean workers accessing laptop farms and crowdsourcing platforms.
Investigators also found that infrastructure connected to the attempted bitFlyer recruitment overlapped with systems linked to the broader campaign.
The National Police Agency and the FBI assessed that Bureau 313 played an important role in both WaterPlum cyberattacks and some overseas revenue-generating operations involving North Korean IT workers.
Companies urged to strengthen remote hiring checks
Japanese authorities advised businesses to carefully verify the identity and location of remote job applicants.
Employers were encouraged to confirm qualifications, technical abilities, residence information, and contact details.
Companies were also advised to investigate situations where an applicant’s claimed location does not match the IP address used during the application or interview process.
Requests for cryptocurrency-based salary payments, inconsistent technical knowledge, reluctance to appear on camera, or suspicious use of VPN and proxy services may also justify additional verification.
The WaterPlum investigation highlights how cyberattacks are increasingly being combined with social engineering and fake recruitment campaigns.
For cryptocurrency companies in particular, stronger hiring procedures and better endpoint security may be essential as attackers continue targeting developers with access to digital assets and sensitive infrastructure.










































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































