FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum

FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum

N
News Editor
2026-09-21 08:44:27
The FBI and Japan’s National Police Agency have publicly attributed a crypto-focused theft campaign to WaterPlum, a North Korean hacking group also known in the security industry as Contagious Interview. According to a warning document released last Friday and reporting by Forbes, the group posed as recruiters offering high-paying remote jobs, then tricked software developers and IT workers into running malware during coding tests or fake troubleshooting tasks. Authorities said the operation hit at least 30,000 devices across more than 100 countries and drained over 7,000 crypto wallets, with total proceeds reaching $10.7 million. The joint warning says the stolen funds and credentials ultimately flowed to Pyongyang. The malware packages used in the scheme included BeaverTail, InvisibleFerret, OtterCookie and a newer strain called StoatWaffle, which could launch after a target opened a blockchain-themed project folder in Visual Studio Code and clicked "Trust." Once active, the malware stole passwords, keystrokes, screenshots, wallet seed phrases and even passport photos. Authorities and security researchers said the campaign shows a shift in focus from major platforms to individual developers. The warning also documented AI face-swapping in interviews, fake job applications, and links to a laptop farm case in Japan.

The FBI and Japan’s National Police Agency have publicly blamed a $10.7 million crypto theft operation on WaterPlum, a North Korean hacking group known in the security industry as Contagious Interview. According to Forbes and a warning released last Friday, the group used fake job offers to lure software developers and IT workers, then stole funds from more than 7,000 crypto wallets.

Authorities said the campaign compromised at least 30,000 devices in more than 100 countries. Stolen funds and credentials ultimately flowed to Pyongyang. The nine-page warning was jointly signed by seven agencies from Japan, the United States, Australia and Germany. Japanese police described the disclosure as a case of public attribution, naming the state actor behind the attacks in an effort to deter future activity.

Fake recruiting as the entry point

WaterPlum is classified by the agencies as an organization under Bureau 313 of North Korea’s Munitions Industry Department. The warning says that same department is also believed to direct some fake remote IT workers operating on behalf of the country.

The attack chain centered on sham hiring processes. Members of the group posed as employers and used lucrative remote positions to target developers and other technical workers worldwide. The front companies were often presented as AI, cryptocurrency or NFT businesses that did not actually exist.

Targets were asked to complete coding tests or help fix a problem on an online video meeting platform. The supposed fix came as a compressed code package. Inside were multiple malware strains: BeaverTail, InvisibleFerret, OtterCookie and a newer sample named StoatWaffle.

The warning says StoatWaffle was hidden inside blockchain-themed project folders. When a developer opened the folder in Visual Studio Code and clicked the "Trust" button, the malware ran automatically. Once executed, it could steal passwords, keylogs, screenshots, crypto wallet seed phrases and any passport photos it found on the device.

Interviewers used AI face swaps and speech tools

The warning also gave unusual detail about the people on the other end of those calls. Interviewers used AI face-swapping software, then switched their cameras off a few minutes into the conversation, blaming network problems and pushing applicants to do the same. They also used text-to-speech tools to practice Japanese pronunciation.

Japanese investigators found a pattern in the group’s activity. During North Korean national holidays, "the attackers would play games, watch soccer matches, and pause their malicious operations."

The operation did not rely only on fake employers. In May 2025, a Japanese crypto exchange received an engineering job application from a candidate who claimed to be born in Malaysia, living in Finland and educated at a European university. Police said the person’s English ability did not match the education and work history listed on the resume, and the applicant was not hired.

Authorities listed other warning signs as well: asking to be paid in cryptocurrency, repeatedly glancing at another monitor during an interview as if reading prompts, and background noise with other voices present.

Average loss was about $1,500 per victim

The warning puts the average theft at about $1,500 per victim. In many cases, the victims believed they were simply taking part in a job interview when their wallets were compromised.

TRM Labs said global crypto hacking losses reached $972 million in the first half of 2026, with $643 million linked to North Korea. Most of that figure came from two April attacks targeting Drift and KelpDAO. TRM also said the total represented only part of North Korea’s crypto-related revenue because it did not include phishing, social engineering or covert operations involving fake IT workers. The warning released last Friday captured part of that missing gray revenue stream.

Forbes noted that North Korean hackers had previously stolen $1.5 billion from Bybit in a single day. The latest campaign was much smaller in dollar terms, but it shifted the target set toward individual developers rather than major trading platforms.

Japan points to its first known laptop farm case

Japanese police also disclosed the country’s first known laptop farm case. In that setup, local accomplices kept multiple work laptops powered on around the clock so overseas operators could log in remotely under borrowed identities and take on outsourced jobs.

According to Jiji Press, those local accomplices lent out their identification documents and bank accounts, and hundreds of millions of yen in illicit proceeds were funneled out of Japan through the arrangement. The warning said WaterPlum hackers and these fake IT workers used the same IP addresses.

Security executives say the operation is highly organized

Boltz Technologies founder and former Goldman Sachs IT vice president Yoon Auh said on the On The Margin podcast: "If someone is determined to target you, it’s very hard to avoid. Other than replacing all of your devices, there’s almost no defense."

Ido Sofer, founder of key management firm Sodot, described the attackers on the same podcast as a structured organization. "They have KPI evaluations, fixed targets, they go to the office, and they have a complete operational strategy. North Korean state-level actors in particular commit enormous resources and will do whatever it takes to achieve the objective. Once a state organization targets an individual, it’s almost impossible to resist."

Dmitry Machikhin of analytics firm BitOK, who previously tracked funds stolen from Bybit, said in an interview: "We’ve identified some of the addresses and wallets used by the Lazarus group to store stolen funds. But that’s as far as we can go. We don’t have the authority to arrest anyone."

Official guidance: assume wallet data has been exposed

Authorities gave direct advice to anyone who had executed a code package sent by a recruiter: assume wallet information has already been compromised.

  • Create a new wallet on a separate, brand-new device
  • Move all assets into the new wallet
  • Store the new seed phrase offline
  • Completely wipe the compromised old device

The case shifts attention from exchange risk to personal laptops. Crypto security discussions have often centered on trading venues, but this attack chain began with a single click during what looked like a routine job interview.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.