NewsCryptoJapan's NPA Says WaterPlum Hackers Infected 30,000 Devices and Stole 7,000+ Crypto Wallet Records

Japan's NPA Says WaterPlum Hackers Infected 30,000 Devices and Stole 7,000+ Crypto Wallet Records

Author: Crypto Ninjas·

Key Takeaways

  • WaterPlum's campaign is believed to have infected more than 30,000 computers in over 100 countries and regions between December 2025 and July 2026.
  • Attackers posed as crypto, AI, and NFT companies on social media and freelance platforms, using coding assignments and file downloads to deliver malware families including OtterCandy, OtterCookie, InvisibleFerret, BeaverTail, and StoatWaffle.
  • More than 7,000 cryptocurrency wallet records were stolen, with private keys and seed phrases targeted, and at least ¥1.7 billion (approximately $10.71 million) in crypto was moved to WaterPlum-controlled wallets.
  • Japanese officials discovered and blocked a laptop farm which North Korean IT workers remotely controlled computers in Japan, using stolen or misused identity documents and virtual private servers to hide their identities.
  • The NPA and FBI concluded that both WaterPlum's malware operations and the fraudulent IT employment scheme were directed by Bureau 313 of the Munitions Industry Department of the Workers' Party of Korea.
Japan's NPA Says WaterPlum Hackers Infected 30,000 Devices and Stole 7,000+ Crypto Wallet Records

Japan's National Police Agency (NPA) has exposed a large-scale cyber campaign that targeted information technology professionals worldwide, with cryptocurrency theft at the center of the operation. The investigation linked the group behind the campaign, tracked WaterPlum, to activity associated with North Korean IT workers and uncovered infrastructure used to conceal their identities and locations.

The findings were detailed in a notice published on the NPA's official website on September 18, 2026. According to the agency, the campaign ran from around December 2025 through July 2026, and more than 30,000 computers across more than 100 countries and regions are believed to have been infected. The targets spanned web developers and designers as well as professionals in the cryptocurrency, blockchain, and Web3 sectors. The breadth of the operation shows how recruitment channels have become an attack surface in their own right for the digital-asset industry, where a developer's machine can hold live wallet credentials alongside source code.

Fake Jobs and Coding Tests Used as Entry Points

WaterPlum allegedly contacted victims through social media, recruitment sites, gig platforms, and freelance marketplaces, frequently posing as trusted firms operating in the crypto, AI, or NFT industries.

Prospective victims were then drawn into online interviews, where candidates were asked to solve software problems or complete coding assignments. In some cases, applicants were instructed to download files from development sites or code repositories in place of a conventional technical assessment. Those files could contain malware capable of compromising the victim's machine.

Malware Families Went After Wallet Credentials

The NPA identified multiple malware families associated with the attack: OtterCandy, OtterCookie, InvisibleFerret, BeaverTail, and StoatWaffle. Once a system is infected, the malware can grant attackers persistent access and extract sensitive information. Observed capabilities included grabbing browser cookies, clipboard contents, keystrokes, screenshots, and files saved on the device.

Wallet credentials posed the greatest danger to cryptocurrency users. According to the NPA, more than 7,000 cryptocurrency wallet records were stolen, and private keys and seed phrases were among the information sought by the attackers. Seed phrases are a single point of failure for self-custodied wallets: whoever obtains one can restore the wallet on another device and move its funds without needing further access to the victim's machine.

The investigation also uncovered a minimum of ¥1.7 billion, approximately $10.71 million, in cryptocurrency moved to wallets operated by WaterPlum. The agency emphasized that this figure reflects funds identified by investigators, not an estimate of all potential losses.

North Korean IT Workers Added a Second Risk

The probe also revealed a separate scheme connected to technology employment. Japanese officials discovered and blocked a “laptop farm” in which computers were stored by a facilitator and controlled remotely from North Korea. The setup allowed those workers to accept jobs while appearing to operate from Japan.

Some of the workers also used stolen or misused identity documents, along with virtual private servers, to mask their actual identities, according to the investigation. Investigators said crypto and other assets valued at upwards of hundreds of millions of yen have been sent abroad in incidents linked to the probe.

The NPA and the FBI concluded that the activities of WaterPlum and some North Korean IT workers were being directed by Bureau 313 of the Munitions Industry Department of the Workers' Party of Korea. The joint attribution connects two schemes — malware-driven theft and fraudulent IT employment — to a single chain of command. For organizations that hired remote developers during the December 2025 to July 2026 window, the notice also provides a concrete timeframe for reviewing how coding tests and file exchanges were handled in their own pipelines.

This report is based on the NPA notice and was first published by CryptoNinjas.