📈 Get daily crypto insights that make you smarter about your money

30,000 Infected Devices and 7,000 Stolen Crypto Wallets: Inside WaterPlum, North Korea Fake-Job Machine

North Korea-linked hacking group WaterPlum has compromised more than 30,000 devices across over 100 countries and stolen information from more than 7,000 cryptocurrency wallets, using fake job interviews to plant malware on developers’ computers, Japan’s National Police Agency reported on September 18.

By Amir Hassan | September 19, 2026

The investigation, conducted with Japan’s National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center and agencies in Australia and Germany, paints one of the clearest pictures yet of how state-directed groups target the people who build crypto and Web3 products. If you work in software, design or anything crypto-adjacent, this report is effectively about your inbox.

How the Fake Job Trap Worked

According to the National Police Agency, WaterPlum approached software developers and IT workers through social media, online job sites, gig platforms and freelance marketplaces. The attackers posed as legitimate artificial intelligence, cryptocurrency and NFT companies or recruitment services, then dangled attractive job offers. Think of it as a phishing email that comes with a salary attached.

During technical interviews or coding tests, candidates were told to download programs hosted on collaborative development platforms and code repositories — sometimes described as fixes for video-conferencing software, sometimes as a required coding assignment. Those files carried malware with names like BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, hidden inside malicious NPM packages, the small bundles of reusable code that developers install daily. Once installed, the malware opened backdoors, allowed remote access, and harvested browser credentials, keystrokes, screenshots and clipboard data — including the private keys and seed phrases that control crypto wallets, plus identity documents like passports stored on affected machines.

The Scale, in Plain Numbers

  • Devices infected — more than 30,000 computers, likely between around December 2025 and July 2026.
  • Geographic reach — victims in over 100 countries and regions, including Japan.
  • Wallet records stolen — information from more than 7,000 cryptocurrency wallets.
  • Traced proceeds — wallets controlled by WaterPlum received at least 1.7 billion yen, roughly 10.7 million USD at the exchange rate used by Japanese authorities.
  • Main targets — web designers, engineers and people working in crypto, blockchain and Web3.

Japanese and U.S. authorities assessed that WaterPlum — associated with the threat activity known as Contagious Interview — and some North Korean IT workers operate under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department. In other words, investigators believe this is not freelance crime but organized foreign-currency generation for the North Korean state.

The Laptop Farm Next Door

The same investigation uncovered Japan’s first known domestic “laptop farm.” A local facilitator kept computers at their residence while North Korean workers, based in North Korea, China or Russia, remotely controlled the machines from abroad. Using identity documents supplied by people living in Japan, the workers impersonated residents to win contracts through crowdsourcing platforms, directing payments into facilitator-controlled bank accounts before sending the money onward. Workers tied to the investigations moved crypto and other assets worth hundreds of millions of yen overseas, the agency said.

The pattern has already been prosecuted elsewhere. In the United States, two men received 18-month prison sentences in 2026 for helping North Korean workers remotely access company laptops, in schemes the Justice Department said involved nearly 70 companies and generated more than 1.2 million USD. A federal judge also ordered the forfeiture of roughly 212,700 USD in stablecoins traced to payment addresses used by North Korean IT workers. Separately, a suspected North Korean applicant tried to land an engineering role at crypto exchange bitFlyer in May 2025 using a stolen identity, VPNs and proxies — but gave vague technical answers, checked another monitor repeatedly during the interview and insisted on being paid in crypto. bitFlyer flagged the behavior and did not hire the person.

What This Means for You

You do not need to be a developer to take the lesson. The single most targeted item in this entire campaign was the seed phrase — the list of words that acts as the master password to a self-custody wallet. Anyone who stores seed phrases or private keys in a browser, a notes app, a clipboard manager or a shared folder is exposed to exactly the kind of information-stealing malware described in the report. Keeping recovery phrases offline, on paper or metal, and never entering them during a “job test” or “meeting software” installation remains the strongest defense.

Security researcher Taylor Monahan of MetaMask previously documented North Korea-linked developers working inside more than 40 DeFi projects over seven years, with job postings, LinkedIn messages and interview processes serving as recurring entry routes. The Japan report confirms the pipeline is industrial in scale.

The Verdict

Thirty thousand infected devices and 7,000 compromised wallets later, the recruiting scam is no longer a niche risk for careless freelancers — it is a core funding mechanism for a state program, run through the same job platforms millions of people use every day. Treat any interview that asks you to install code before you are hired as hostile until proven otherwise, and keep your keys off any machine that touches the internet.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

16 thoughts on “30,000 Infected Devices and 7,000 Stolen Crypto Wallets: Inside WaterPlum, North Korea Fake-Job Machine”

  1. 7,000 wallets and 30,000 machines from fake interviews, and the actual defense is boring: hardware wallet plus a disposable VM for anything a recruiter sends

    1. disposable vm plus hardware wallet is the whole toolkit honestly. also rotate the github pat after any interview process, that token outlives the laptop

    2. boring is right, but the npm angle is the scary part. your package.json is the attack surface now, a hardware wallet doesnt help when the keys get typed into the infected machine first

  2. 7,000 wallets drained through fake recruiter DMs. if an HR person sends you a video call link, verify the domain twice, then a third time

    1. verify the domain AND check how old the linkedin profile is. a two week old recruiter profile is the tell most people miss

      1. ran that check on a recruiter last month, company website was 9 days old and the linkedin had 3 connections. saved by dns records lol

  3. OtterCookie running through npm install chains means the repo itself is the trap now. code review protects users, nothing protects the reviewer

  4. Been through three of these interviews last month. Recruiter profile two weeks old, company domain one letter off. They’re getting better at it.

    1. Domain one letter off is the oldest trick there is. I forward every recruiter domain to security now, they caught two clone domains last quarter alone

  5. North Korea runs an entire fake employment pipeline and somehow recruiter verification is still optional. 30,000 devices, wild

  6. OtterCookie and StoetWaffle sound like plush toys, not credential stealers. 30,000 machines across 100 countries is basically a census of every mid level dev who answered a recruiter dm.

  7. fake job interviews as the infection vector is brutal because devs are exactly the people convinced they would never fall for it. 30k devices across 100+ countries

    1. they’re past basic phishing links now, running actual multi-stage interviews with HR-looking calendars and everything. the professionalism is the scary part

  8. NPA plus FBI plus DoD Cyber Crime all on the same press release tells you how much of this is quietly state-directed. 7k wallets drained and we hear about it years later

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$81,842.00+1.1%ETH$2,647.55+1.9%SOL$111.72-0.1%BNB$766.43+1.0%XRP$1.44+3.8%ADA$0.2285+4.3%DOGE$0.0895+1.9%DOT$1.13-0.8%AVAX$9.66+19.6%LINK$12.59+3.4%UNI$8.90+0.3%ATOM$1.74+3.4%LTC$57.97+3.3%ARB$0.2084-3.2%NEAR$3.60-2.3%FIL$1.02+14.8%SUI$0.8533+6.5%BTC$81,842.00+1.1%ETH$2,647.55+1.9%SOL$111.72-0.1%BNB$766.43+1.0%XRP$1.44+3.8%ADA$0.2285+4.3%DOGE$0.0895+1.9%DOT$1.13-0.8%AVAX$9.66+19.6%LINK$12.59+3.4%UNI$8.90+0.3%ATOM$1.74+3.4%LTC$57.97+3.3%ARB$0.2084-3.2%NEAR$3.60-2.3%FIL$1.02+14.8%SUI$0.8533+6.5%
Scroll to Top