Law enforcement says a North Korea-linked group called WaterPlum infected more than 30,000 computers across 100+ countries and stole data from over 7,000 cryptocurrency wallets. Wallets controlled by the group received at least $10.71 million between December 2025 and July 2026. The attackers posed as recruiters, delivered malware via code-sharing files and operated a remote "laptop farm." Authorities advise developers to run recruiter-provided code only in sandboxed environments and use hardware wallets for significant funds.
North Korea-Linked 'WaterPlum' Hackers Infect 30,000+ Devices, Drain $10.71M From Crypto Wallets

A hacking group linked to North Korea, tracked as WaterPlum (also known as Contagious Interview), infected more than 30,000 computers across 100+ countries and exfiltrated data from over 7,000 cryptocurrency wallets, Japan's National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI) said.
What Happened
The agencies reported that wallets controlled by the group received at least $10.71 million in digital assets between December 2025 and July 2026. WaterPlum targeted software developers and IT professionals by posing as headhunters for artificial intelligence, cryptocurrency and NFT companies, contacting victims via social media, job boards and freelance platforms.
How The Attack Worked
Targets were invited to take part in technical interviews or complete coding tests. The attackers instructed candidates to download files hosted on legitimate code-sharing platforms, often claiming a broken video call or that the assignment required the download. Those files contained malware that:
- Harvested browser-stored passwords;
- Captured screenshots and logged keystrokes;
- Searched for and stole private keys that grant access to cryptocurrency wallets.
"WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities," the NPA and FBI said in a joint advisory.
Scale, Research And Attribution
In August, an independent researcher who spent 22 months inside the group's servers mapped 1,640 victims in 57 countries; the official law-enforcement tally released later is roughly 18 times larger. Investigators also identified and dismantled what they describe as North Korea's first known "laptop farm": local accomplices kept machines in their homes while North Korean workers abroad remotely controlled them and posed as Japanese residents to win freelance work.
Links To North Korean Institutions
Authorities said the NPA and FBI assess WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers' Party of Korea. In one notable case, a suspected North Korean applied for a role at Japanese exchange bitFlyer in May 2025 using a stolen résumé, demanded payment in cryptocurrency, refused to relocate and appeared to read answers from a second screen; he was not hired.
Practical Advice For Engineers And Developers
Investigators advise extreme caution when interacting with recruiter-supplied code and candidate toolchains:
- Run any recruiter-provided or third-party code only inside a clearly isolated sandbox or virtual machine that is separated from your real files and keys.
- Do not download or run executables from unverified sources; prefer reviewing code in read-only mode on separate systems.
- Use hardware wallets or cold storage for significant funds and enable multi-factor authentication where possible.
- Verify recruiter identities independently, and be skeptical of requests for crypto payment or unusual interview workflows.
Takeaway
The WaterPlum campaign highlights a persistent and sophisticated social-engineering vector that leverages legitimate hiring processes and platforms to deliver data-stealing malware. Developers and hiring teams should tighten operational security around code sharing and interview tooling.
Sources: Joint advisory from the Japan National Police Agency and the U.S. FBI; reporting by BeInCrypto.
Help us improve.



























