North Korean Hackers Infect 30,000 Devices, Target 7,000 Crypto Wallets
Key Takeaways
- •North Korea-linked hackers infected more than 30,000 devices across over 100 countries and regions between December 2025 and July 2026 in the WaterPlum campaign, stealing information from more than 7,000 cryptocurrency wallets, according to Japan's NPA and the FBI.
- •The attackers posed as recruiters from cryptocurrency, artificial intelligence, and NFT companies on social media, job sites, freelance platforms, and gig-work platforms, prompting victims to download malware through coding tasks and technical interviews.
- •WaterPlum used multiple malware families, including BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle, capable of stealing passwords, screenshots, keyboard input, clipboard data, private keys, and seed phrases.
- •Wallets controlled by the attackers received at least $10.71 million in cryptocurrency, an amount the National Police Agency estimated at approximately ¥1.7 billion.
- •The NPA and FBI believe WaterPlum and some North Korean IT activities are connected to Bureau 313 within the Workers' Party Central Committee, and the investigation uncovered a suspected North Korean IT worker who applied to bitFlyer using another person's identity through VPN services.

North Korea-linked hackers infected more than 30,000 devices and stole information from over 7,000 cryptocurrency wallets in a campaign aimed at victims in more than 100 countries and regions, Japan's National Police Agency (NPA) and the FBI have reported. The attacks ran from December 2025 to July 2026, with Japanese investigators assisted by the FBI and other foreign agencies. The findings are detailed in a report published by the NPA on September 18, 2026, and the disclosure forms part of ongoing cooperation between Japanese authorities and their foreign counterparts on North Korea-linked cyber activity.
The operation, tracked under the name WaterPlum and also referred to as Contagious Interview, primarily targeted IT professionals. According to investigators, the group used fake job offers to reach developers and others in the technology industry, with web designers, engineers, blockchain workers, and Web3 professionals counted among the main victims.
North Korean Hackers Infect Over 30,000 Devices, Steal Data From 7,000 Crypto Wallets
Japan's National Police Agency and the FBI reported that North Korea-linked WaterPlum infected over 30,000 devices across more than 100 countries and regions from December 2025 to July 2026,… pic.twitter.com/72mKuQwein
— Wu Blockchain (@WuBlockchain) September 18, 2026
WaterPlum Used Fake Jobs to Target Crypto Professionals
Japanese authorities said WaterPlum contacted job seekers through social media and also leveraged online job sites, freelance websites, and gig-work platforms to find targets. In these interactions, the attackers allegedly impersonated cryptocurrency, artificial intelligence, and NFT companies, and posed as recruitment agencies in order to appear genuine.
Once contact was established, victims were asked to complete coding tasks or take part in technical interviews — steps that could involve downloading malware. Malicious files were placed on online development platforms and code repositories, where they were subsequently used by victims in technical assignments or software troubleshooting.
WaterPlum was found to be using multiple malware families across the attacks: BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle. According to the agencies, the malware could create access to infected computers and steal passwords, screenshots, keyboard input, and clipboard data. For the targeted developers and Web3 professionals, that combination of stolen information could expose both work activity and data handled during cryptocurrency-related tasks.
The attackers also went after cryptocurrency wallet information. This included private keys, seed phrases, and other sensitive wallet data. Authorities discovered that wallets controlled by WaterPlum received at least $10.71 million in cryptocurrency, an amount the National Police Agency estimated at approximately ¥1.7 billion.
In total, the infections impacted more than 30,000 PCs across over 100 countries and regions, with the primary targets working in web design, engineering, blockchain, and the broader Web3 sector.
North Korean IT Workers Used "Laptop Farms"
The investigation also brought to light networks of North Korean IT workers and local supporters. The workers are said to have used remotely controlled computers located in supporters' homes — arrangements the Japanese government has called "laptop farms." These setups allowed the employees to conceal their true identities when working online. Some workers also relied on virtual private servers and crowdsourcing, reportedly operating from North Korea, China, Russia, Africa, and Southeast Asia.
Separately, the investigation uncovered a suspected North Korean IT worker who applied to bitFlyer, the Japanese cryptocurrency exchange. In May 2025, the applicant sought an engineering position using another person's identity information and accessed the recruitment website through VPN services.
Investigators noticed several suspicious elements during the interview. The applicant's technical responses were unclear, even though he claimed extensive professional experience. The applicant also refused to relocate to Japan and demanded that his salary be paid in cryptocurrencies. In addition, voices of other people were allegedly heard during the interview.
Matching IP addresses were also discovered linking WaterPlum and North Korean IT worker activity. One of these addresses was additionally connected to the bitFlyer recruitment activity, according to the investigation.
The NPA and FBI believe that WaterPlum and some North Korean IT activities are connected to Bureau 313, a body within North Korea's Workers' Party Central Committee.
Lastly, the authorities urged developers not to run unknown code on work computers. They also suggested using virtual machines and limited, controlled environments when handling new projects.
Source: Live Bitcoin News