A hacking group linked to North Korea infected more than 30,000 computers across over 100 countries and stole information from more than 7,000 cryptocurrency wallets — all by pretending to offer people jobs. Japan’s National Police Agency disclosed the operation on Sept. 18, in a joint investigation conducted with the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, and agencies in Australia and Germany.
By Imani Davis | September 18, 2026
The Hook: A Job Interview That Robs You
The group, tracked as WaterPlum, targeted software developers and IT workers through social media, online job sites, gig platforms, and freelance marketplaces. The attackers posed as legitimate artificial intelligence, cryptocurrency, and NFT companies — or as recruitment services — and dangled attractive job opportunities in front of their targets.
During technical interviews or coding tests, candidates were instructed to download malicious programs hosted on collaborative development platforms and code repositories. Some victims were told the files were needed to fix video conferencing problems or complete a coding assignment. The moment they ran the file, their device belonged to the attackers. Investigators found the infections likely occurred between roughly December 2025 and July 2026, with web designers, engineers, and people working in crypto, blockchain, and Web3 among the main targets.
On-Chain Evidence: 7,000 Wallets and 10.7 Million USD
More than 7,000 cryptocurrency wallet records were stolen during the infections, and wallets controlled by WaterPlum received at least 1.7 billion yen — roughly 10.7 million USD at the exchange rate used by Japanese authorities. That figure represents the minimum observed inflow to attacker-controlled wallets, so the true damage may be larger.
- 30,000+ — computers likely infected across more than 100 countries and regions
- 7,000+ — crypto wallet records stolen
- 10.7 million USD — minimum received by WaterPlum-controlled wallets (1.7 billion yen)
- BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle — malware families delivered through malicious NPM packages
Once a device was compromised, attackers established backdoors and used remote access tools to keep their foothold and move through affected systems. Information-stealing malware then extracted browser credentials, keystrokes, screenshots, and clipboard data. The crown jewels: private keys and seed phrases for cryptocurrency wallets, along with identity documents such as passports and driver’s licenses stored on affected computers or shared folders.
The Core Conflict: Bureau 313 and the Laptop Farms
Japanese and U.S. authorities assessed that WaterPlum — associated with the threat activity known as Contagious Interview — and some North Korean IT workers operate under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department. In other words, this is not freelance crime; it is state-organized revenue generation for a sanctioned regime, run through two complementary schemes.
The first scheme steals. The second scheme earns: North Korean IT workers secretly take remote jobs at Western companies while concealing their locations. Japanese investigators said they dismantled the first known domestic “laptop farm” connected to this activity — a bank of computers that North Korean workers remotely controlled to take jobs while appearing to work from Japan. In a related case, a suspected North Korean IT worker applied for an engineering role at the Japanese exchange bitFlyer in 2025 but was identified before being hired.
The scale of infiltration can be startling. Security researcher Taylor Monahan of MetaMask previously documented that North Korea-linked developers had worked inside more than 40 DeFi projects over seven years — meaning some of the code running in crypto today may have been written by the same ecosystem that hunts its users.
Market Implications: Why Ordinary Holders Should Care
You do not need to be a developer to be affected by this campaign. Developers build the wallets, exchanges, and protocols that everyone else uses. If a developer’s laptop is compromised, the malware can ride along into code repositories, build systems, and company networks — which is how single infections become platform-level disasters. Stolen credentials and identity documents also fuel further fraud that erodes trust in the entire industry.
For anyone in tech-adjacent work, the practical warning is simple: never run files downloaded as part of a job interview or coding test without isolating them first. Recruiters who insist you install software from a link, diagnose a video call problem with a download, or complete a task inside an unfamiliar repository are exhibiting the exact pattern Japanese and U.S. authorities just documented across 100 countries.
The Verdict: Vigilance Is the Only Defense
Hardware wallets remain one of the strongest defenses for regular holders — private keys stored on a device that never touches an internet-connected computer cannot be scraped by clipboard malware. Keeping seed phrases off laptops and shared folders, verifying recruiter identities independently, and treating any interview that requires downloads as a red flag are the baseline habits of 2026.
The joint disclosure by Japan, the United States, Australia, and Germany is a rare coordinated window into how state-backed crypto theft actually operates — and a reminder that the cheapest attack in this industry is still the oldest one: convincing a human to open the door themselves.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
7000 wallets drained because people opened a “take home assignment” file. never run interview code on the machine holding your keys, basic opsec
^ this. WaterPlum also sent PDFs with macros, any recruiter shipping executables is a red flag the size of pyongyang
or just do the take-home in a throwaway VM, costs nothing. 7000 drained wallets says the technical interview filter failed exactly the people it should protect
7000 wallets drained through fake recruiter DMs. the job market is so bad people click anything that looks like an offer, sad state of affairs
rough market sure, but a recruiter pushing an executable over telegram was never a real offer. desperation makes people skip the basics
NPA publishing this joint with the FBI and DoD suggests the counterintelligence side considers WaterPlum a state priority now, not just a cybercrime nuisance.
^ this. also devs, the payload came during technical interviews. never run their “coding challenge” file on a machine with your wallets on it
30k machines across 100 countries and the joint advisory only drops now, months after the campaigns. useful info, brutal lag
the lag is intentional though. disclosing the indicators earlier burns the collection operation. classic sequencing: monitor, attribute, then warn