FBI, Japanese police tie $10.7 million crypto theft campaign to North Korean group WaterPlum
The FBI and Japan’s National Police Agency have publicly attributed a crypto-focused theft campaign to WaterPlum, a North Korean hacking group also known in the security industry as Contagious Interview. According to a warning document released last Friday and reporting by Forbes, the group posed as recruiters offering high-paying remote jobs, then tricked software developers and IT workers into running malware during coding tests or fake troubleshooting tasks. Authorities said the operation hit at least 30,000 devices across more than 100 countries and drained over 7,000 crypto wallets, with total proceeds reaching $10.7 million. The joint warning says the stolen funds and credentials ultimately flowed to Pyongyang. The malware packages used in the scheme included BeaverTail, InvisibleFerret, OtterCookie and a newer strain called StoatWaffle, which could launch after a target opened a blockchain-themed project folder in Visual Studio Code and clicked "Trust." Once active, the malware stole passwords, keystrokes, screenshots, wallet seed phrases and even passport photos. Authorities and security researchers said the campaign shows a shift in focus from major platforms to individual developers. The warning also documented AI face-swapping in interviews, fake job applications, and links to a laptop farm case in Japan.


