NewsCryptoNorth Korea-Linked WaterPlum Hackers Infect 30,000 Devices, Steal $10.71 Million in Crypto

North Korea-Linked WaterPlum Hackers Infect 30,000 Devices, Steal $10.71 Million in Crypto

Author: Crypto Adventure·

Key Takeaways

  • The WaterPlum campaign, widely known as Contagious Interview, infected at least 30,000 computers across more than 100 countries and compromised funds or credentials tied to over 7,000 cryptocurrency wallets.
  • Operators as recruiters from legitimate cryptocurrency, AI, and NFT companies, tricking candidates into running malicious files delivering payloads such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
  • The FBI and Japan's National Police Agency assess that WaterPlum actors operate under the 313 General Bureau of North Korea's Munitions Industry Department and found overlap with North Korean IT-worker schemes, including shared IP addresses used for laptop farms.
  • The advisory warns that removing malware does not guarantee stored wallet data is safe, so users should create a new wallet on a clean device and transfer assets using a newly generated recovery phrase, alongside a full operating-system reset.
  • The campaign stole at least 1.7 billion Japanese yen ($10.71 million) and adds to more than $2 billion in cryptocurrency stolen by DPRK-linked groups in 2025, including the $1.5 billion Bybit theft attributed to TraderTraitor.
North Korea-Linked WaterPlum Hackers Infect 30,000 Devices, Steal $10.71 Million in Crypto

A North Korea-linked hacking operation infected at least 30,000 computers across more than 100 countries and compromised funds or credentials tied to over 7,000 cryptocurrency wallets through fake recruitment campaigns aimed at developers and IT professionals, according to a joint advisory issued on September 18.

The campaign, tracked as WaterPlum and widely known as Contagious Interview, stole at least 1.7 billion Japanese yen, or $10.71 million, in cryptocurrency between December 2025 and July 2026. The advisory was released by Japan's National Police Agency and National Cybersecurity Office together with the FBI, the U.S. Defense Department's Cyber Crime Center, and agencies in Australia and Germany.

Fake Recruiters Target Crypto and AI Developers

WaterPlum operators pose as recruiters or prospective employers representing legitimate cryptocurrency, artificial intelligence, and NFT companies. Targets are approached through social networks, job platforms, freelance marketplaces, and recruitment services, then invited to technical interviews or coding assessments.

Candidates are instructed to download and execute malicious files, often under the pretext of completing a coding task or fixing a video-conferencing problem. The payloads include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, delivered through malicious NPM packages, code repositories, and Visual Studio Code projects.

Once installed, the malware can capture browser credentials, clipboard contents, keystrokes, and screenshots while searching for cryptocurrency private keys and seed phrases. Remote-access tools preserve access to infected machines and can provide a path into networks belonging to the victim's employer or clients.

The attack pattern extends fake crypto job interview campaigns that have increasingly targeted developers through coding assignments, fake meeting software, and malicious repositories.

FBI and NPA Link WaterPlum to North Korean State Structure

The FBI and the NPA assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which sits under the Central Committee of North Korea's Workers' Party.

Investigators also found overlap between the hacking operation and North Korean IT-worker schemes. The same IP addresses were used to access laptop farms, crowdsourcing services, and applications for positions at a Japanese cryptocurrency exchange. Japan dismantled one such laptop farm after identifying computers remotely controlled by North Korean workers.

infiltration risks surfaced this year when MetaMask removed a North Korea-linked contractor after the developer had spent about a month contributing to its codebase. The episode shows how North Korea-linked operatives can reach crypto organizations through ordinary employment and code-contribution channels.

Compromised Wallets Should Be Replaced

The joint advisory warns that removing detected malware does not guarantee that previously stored wallet information remains secure. Users who suspect a device was compromised are advised to disconnect it from the internet, create a new wallet on a separate clean device, and move assets to new addresses with a newly generated recovery phrase. For self-custody users, this treats the existing recovery phrase as exposed even if the device is later cleaned.

Authorities also recommend a full operating-system reset on infected machines and advise developers to run unfamiliar code only inside isolated virtual machines or sandboxes.

The latest campaign adds another route to North Korea's crypto revenue operations after DPRK-linked groups stole more than $2 billion in cryptocurrency during 2025, including the $1.5 billion Bybit theft attributed by the FBI to TraderTraitor.