📈 Get daily crypto insights that make you smarter about your money

North Korean Hackers Infected 30,000 Computers and Drained 7,000 Crypto Wallets Using Fake Job Offers

A hacking group linked to North Korea infected more than 30,000 computers across over 100 countries and stole information from more than 7,000 cryptocurrency wallets — all by pretending to offer people jobs. Japan’s National Police Agency disclosed the operation on Sept. 18, in a joint investigation conducted with the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, and agencies in Australia and Germany.

By Imani Davis | September 18, 2026

The Hook: A Job Interview That Robs You

The group, tracked as WaterPlum, targeted software developers and IT workers through social media, online job sites, gig platforms, and freelance marketplaces. The attackers posed as legitimate artificial intelligence, cryptocurrency, and NFT companies — or as recruitment services — and dangled attractive job opportunities in front of their targets.

During technical interviews or coding tests, candidates were instructed to download malicious programs hosted on collaborative development platforms and code repositories. Some victims were told the files were needed to fix video conferencing problems or complete a coding assignment. The moment they ran the file, their device belonged to the attackers. Investigators found the infections likely occurred between roughly December 2025 and July 2026, with web designers, engineers, and people working in crypto, blockchain, and Web3 among the main targets.

On-Chain Evidence: 7,000 Wallets and 10.7 Million USD

More than 7,000 cryptocurrency wallet records were stolen during the infections, and wallets controlled by WaterPlum received at least 1.7 billion yen — roughly 10.7 million USD at the exchange rate used by Japanese authorities. That figure represents the minimum observed inflow to attacker-controlled wallets, so the true damage may be larger.

  • 30,000+ — computers likely infected across more than 100 countries and regions
  • 7,000+ — crypto wallet records stolen
  • 10.7 million USD — minimum received by WaterPlum-controlled wallets (1.7 billion yen)
  • BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle — malware families delivered through malicious NPM packages

Once a device was compromised, attackers established backdoors and used remote access tools to keep their foothold and move through affected systems. Information-stealing malware then extracted browser credentials, keystrokes, screenshots, and clipboard data. The crown jewels: private keys and seed phrases for cryptocurrency wallets, along with identity documents such as passports and driver’s licenses stored on affected computers or shared folders.

The Core Conflict: Bureau 313 and the Laptop Farms

Japanese and U.S. authorities assessed that WaterPlum — associated with the threat activity known as Contagious Interview — and some North Korean IT workers operate under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department. In other words, this is not freelance crime; it is state-organized revenue generation for a sanctioned regime, run through two complementary schemes.

The first scheme steals. The second scheme earns: North Korean IT workers secretly take remote jobs at Western companies while concealing their locations. Japanese investigators said they dismantled the first known domestic “laptop farm” connected to this activity — a bank of computers that North Korean workers remotely controlled to take jobs while appearing to work from Japan. In a related case, a suspected North Korean IT worker applied for an engineering role at the Japanese exchange bitFlyer in 2025 but was identified before being hired.

The scale of infiltration can be startling. Security researcher Taylor Monahan of MetaMask previously documented that North Korea-linked developers had worked inside more than 40 DeFi projects over seven years — meaning some of the code running in crypto today may have been written by the same ecosystem that hunts its users.

Market Implications: Why Ordinary Holders Should Care

You do not need to be a developer to be affected by this campaign. Developers build the wallets, exchanges, and protocols that everyone else uses. If a developer’s laptop is compromised, the malware can ride along into code repositories, build systems, and company networks — which is how single infections become platform-level disasters. Stolen credentials and identity documents also fuel further fraud that erodes trust in the entire industry.

For anyone in tech-adjacent work, the practical warning is simple: never run files downloaded as part of a job interview or coding test without isolating them first. Recruiters who insist you install software from a link, diagnose a video call problem with a download, or complete a task inside an unfamiliar repository are exhibiting the exact pattern Japanese and U.S. authorities just documented across 100 countries.

The Verdict: Vigilance Is the Only Defense

Hardware wallets remain one of the strongest defenses for regular holders — private keys stored on a device that never touches an internet-connected computer cannot be scraped by clipboard malware. Keeping seed phrases off laptops and shared folders, verifying recruiter identities independently, and treating any interview that requires downloads as a red flag are the baseline habits of 2026.

The joint disclosure by Japan, the United States, Australia, and Germany is a rare coordinated window into how state-backed crypto theft actually operates — and a reminder that the cheapest attack in this industry is still the oldest one: convincing a human to open the door themselves.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

11 thoughts on “North Korean Hackers Infected 30,000 Computers and Drained 7,000 Crypto Wallets Using Fake Job Offers”

  1. 7000 wallets drained because people opened a “take home assignment” file. never run interview code on the machine holding your keys, basic opsec

    1. or just do the take-home in a throwaway VM, costs nothing. 7000 drained wallets says the technical interview filter failed exactly the people it should protect

      1. a vm with snapshots costs nothing and catches most of this. the rest is people pasting seed phrases into a company onboarding form, which no vm fixes

  2. 7000 wallets drained through fake recruiter DMs. the job market is so bad people click anything that looks like an offer, sad state of affairs

    1. rough market sure, but a recruiter pushing an executable over telegram was never a real offer. desperation makes people skip the basics

  3. NPA publishing this joint with the FBI and DoD suggests the counterintelligence side considers WaterPlum a state priority now, not just a cybercrime nuisance.

    1. ^ this. also devs, the payload came during technical interviews. never run their “coding challenge” file on a machine with your wallets on it

  4. 30k machines across 100 countries and the joint advisory only drops now, months after the campaigns. useful info, brutal lag

    1. the lag is intentional though. disclosing the indicators earlier burns the collection operation. classic sequencing: monitor, attribute, then warn

      1. monitor attribute then warn works great for states, less so for the 7000 people already drained. somewhere between opsec and negligence

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$81,264.00+6.1%ETH$2,640.84+7.7%SOL$113.91+12.8%BNB$766.39+4.6%XRP$1.40+8.0%ADA$0.2222+10.0%DOGE$0.0880+7.6%DOT$1.14+6.8%AVAX$8.28+9.1%LINK$12.36+8.9%UNI$9.04+17.9%ATOM$1.69+8.3%LTC$57.05+5.8%ARB$0.2213+25.5%NEAR$3.68+21.0%FIL$0.9197+12.4%SUI$0.8105+10.5%BTC$81,264.00+6.1%ETH$2,640.84+7.7%SOL$113.91+12.8%BNB$766.39+4.6%XRP$1.40+8.0%ADA$0.2222+10.0%DOGE$0.0880+7.6%DOT$1.14+6.8%AVAX$8.28+9.1%LINK$12.36+8.9%UNI$9.04+17.9%ATOM$1.69+8.3%LTC$57.05+5.8%ARB$0.2213+25.5%NEAR$3.68+21.0%FIL$0.9197+12.4%SUI$0.8105+10.5%
Scroll to Top