North Korea’s WaterPlum hackers stole $10.7M in crypto, Japan and allies say

- Japan’s police, the FBI, and agencies in Australia and Germany said the WaterPlum North Korean group stole about $10.71 million in crypto.
- The campaign infected more than 30,000 devices in over 100 countries and drained credentials from roughly 7,000 crypto accounts.
- For developers and freelancers, it is a direct warning that fake coding tests and interview downloads are a live threat funding Pyongyang.
The National Police Agency of Japan, alongside the FBI and security agencies in Australia and Germany, have put a name to a North Korean group that pretended to be tech recruiters while stealing cryptocurrency from IT professionals globally. They diverted 1.7 billion yen (about $10.71 million) worth of assets to North Korea.
The crew is called WaterPlum but uses “Contagious Interview” as an alias, and they targeted victims all over the globe, including Japan, the US, Europe, and beyond, according to a joint advisory the seven agencies released on Friday, September 18, 2026.
Seven agencies, one public attribution
The advisory has on it the names of seven agencies: Japan’s National Cybersecurity Office, the NPA, the FBI, the Department of Defense Cyber Crime Center, Australia’s ASD Cyber Security Centre, as well as Germany’s BND and BfV.
The announcement was made under a “public attribution” framework, a move aimed at deterring future attacks by exposing the state or group behind a malicious cyber-attack.
Based on the assessment of the NPA and FBI, WaterPlum’s hackers, alongside a group of North Korean IT workers, are under the command of the 313 General Bureau of the Munitions Industry Department, a unit under the auspices of the Central Committee of the Workers’ Party of Korea. That means the operation was part of a larger plan Pyongyang used to fund its weapons program. US intelligence agencies have leveled the same charge in the past during an episode of North Korean crypto theft, a charge the North Korean regime denies vehemently.
How North Korea’s fake job scheme worked
The scheme worked this way: the hackers pretended to be hiring managers at AI firms, crypto ventures, and NFT startups, offering irresistible job offers to software developers. Applicants would then sit for technical interviews or complete coding assignments before being instructed to download and run files as part of the assessment.
The downloaded files were corrupted with malware. There were various strains of malware in the Node Package Manager packages. They include: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. After installation, the code created a backdoor, maintaining access via remote-access trojans, and extracted browser passwords, keystrokes, screenshots, and the private keys and seed phrases that are used to access crypto wallets
From December last year to July of this year, the operation corrupted over 30,000 devices in more than 100 countries and sensitive information belonging to about 7,000 cryptocurrency accounts.
A laptop farm destroyed in Japan
The operation was in two parts, and the second part involved labor. Based on the NPA’s announcement, some North Korean IT workers, resident in North Korea, China, and Russia, obtained remote programming and web-development contracts surreptitiously, while sending their salaries back to North Korea.
In total, hundreds of millions of yen were routed back to North Korea over the years.
To conceal the physical origin of that work, the network made use of locals who operated laptop farms and virtual private servers for the hackers. Authorities in Japan have spotted, investigated, and stopped a laptop farm run by an enabler in Japan, a first of its kind.
Part of a widening North Korean operation
The advisory sheds more light on a growing pattern that has developed over the months. There’s been a 420% spike in malware written to public blockchains. With a huge chunk of it originating in North Korea and Iran.
North Korea’s crypto theft was classified as a significant security threat during a G7 leaders meeting in June this year. This was after approximately $6.75 billion was found to have been stolen since 2016 by actors with North Korean links.
The recruitment lure is a recurring signature. Black Hat researcher Vangelis Stykas said this year, he had traced North Korean hackers into 1,640 companies across 57 countries, often by baiting developers with fake job offers that install malware, as Cryptopolitan reported.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
What is WaterPlum and who is behind it?
WaterPlum, also called "Contagious Interview," is a North Korean cyber group that Japan's NPA and the FBI assess operates under the 313 General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea's Central Committee.
How much cryptocurrency did WaterPlum steal?
The joint advisory says the group transferred 1.7 billion yen, about $10.71 million or roughly 14.5 billion Korean won, in stolen crypto to North Korea, after compromising credentials for around 7,000 cryptocurrency accounts.
How did the hackers infect their victims?
They impersonated recruiters at AI, crypto and NFT companies and asked developers to complete coding tests or interviews, then had them download files carrying malware such as BeaverTail, InvisibleFerret and OtterCookie that stole wallet keys and login data.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















