BackJapan NPA

Japan NPA

North Korea
2026-09-21 08:44:27

FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum

The FBI and Japan’s National Police Agency have publicly attributed a crypto-focused theft campaign to WaterPlum, a North Korean hacking group also known in the security industry as Contagious Interview. According to a warning document released last Friday and reporting by Forbes, the group posed as recruiters offering high-paying remote jobs, then tricked software developers and IT workers into running malware during coding tests or fake troubleshooting tasks. Authorities said the operation hit at least 30,000 devices across more than 100 countries and drained over 7,000 crypto wallets, with total proceeds reaching $10.7 million. The joint warning says the stolen funds and credentials ultimately flowed to Pyongyang. The malware packages used in the scheme included BeaverTail, InvisibleFerret, OtterCookie and a newer strain called StoatWaffle, which could launch after a target opened a blockchain-themed project folder in Visual Studio Code and clicked "Trust." Once active, the malware stole passwords, keystrokes, screenshots, wallet seed phrases and even passport photos. Authorities and security researchers said the campaign shows a shift in focus from major platforms to individual developers. The warning also documented AI face-swapping in interviews, fake job applications, and links to a laptop farm case in Japan.

30
FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum
North Korea h
2026-09-20 06:15:22

Japan, FBI and partners expose North Korean fake recruiting operation targeting crypto developers

Japan’s National Police Agency, the U.S. Federal Bureau of Investigation and other international agencies said on Sept. 18 that a North Korean hacking group known as WaterPlum, also called “Contagious Interview,” has been posing as recruiters and crypto companies to trick developers into running malware. According to the joint disclosure, the group infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026, moving funds or stealing account credentials from more than 7,000 crypto wallets, with at least $10.71 million in crypto assets involved. Authorities said the campaign differs from earlier attacks focused on exchanges and large institutions because it pushes deeper into the individual layer of the industry, targeting developers, freelancers and other Web3 workers. The malware is often delivered through coding tests, project repositories and fake troubleshooting tasks tied to video interviews. The agencies named several malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, and warned that some projects abuse VS Code task settings to execute code automatically. The notice also linked the operation to North Korean IT workers who allegedly use stolen identity documents to seek overseas jobs, including at crypto firms. Japanese authorities said they had identified, for the first time, a Japan-based remote work hub used to help such workers disguise their location and identity.

150
Japan, FBI and partners expose North Korean fake recruiting operation targeting crypto developers