The National Police Agency of Japan, alongside the FBI and security agencies in Australia and Germany, have put a name to a North Korean group that pretended to be tech recruiters while stealing cryptocurrency from IT professionals globally. They diverted 1.7 billion yen (about $10.71 million) worth of assets to North Korea.
The crew is called WaterPlum but uses “Contagious Interview” as an alias, and they targeted victims all over the globe, including Japan, the US, Europe, and beyond, according to a joint advisory the seven agencies released on Friday, September 18, 2026.
Seven agencies, one public attribution
The advisory has on it the names of seven agencies: Japan’s National Cybersecurity Office, the NPA, the FBI, the Department of Defense Cyber Crime Center, Australia’s ASD Cyber Security Centre, as well as Germany’s BND and BfV.
The announcement was made under a “public attribution” framework, a move aimed at deterring future attacks by exposing the state or group behind a malicious cyber-attack.
Based on the assessment of the NPA and FBI, WaterPlum’s hackers, alongside a group of North Korean IT workers, are under the command of the 313 General Bureau of the Munitions Industry Department, a unit under the auspices of the Central Committee of the Workers’ Party of Korea. That means the operation was part of a larger plan Pyongyang used to fund its weapons program. US intelligence agencies have leveled the same charge in the past during an episode of North Korean crypto theft, a charge the North Korean regime denies vehemently.
How North Korea’s fake job scheme worked
The scheme worked this way: the hackers pretended to be hiring managers at AI firms, crypto ventures, and NFT startups, offering irresistible job offers to software developers. Applicants would then sit for technical interviews or complete coding assignments before being instructed to download and run files as part of the assessment.
The downloaded files were corrupted with malware. There were various strains of malware in the Node Package Manager packages. They include: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. After installation, the code created a backdoor, maintaining access via remote-access trojans, and extracted browser passwords, keystrokes, screenshots, and the private keys and seed phrases that are used to access crypto wallets
From December last year to July of this year, the operation corrupted over 30,000 devices in more than 100 countries and sensitive information belonging to about 7,000 cryptocurrency accounts.
A laptop farm destroyed in Japan
The operation was in two parts, and the second part involved labor. Based on the NPA’s announcement, some North Korean IT workers, resident in North Korea, China, and Russia, obtained remote programming and web-development contracts surreptitiously, while sending their salaries back to North Korea.
In total, hundreds of millions of yen were routed back to North Korea over the years.
To conceal the physical origin of that work, the network made use of locals who operated laptop farms and virtual private servers for the hackers. Authorities in Japan have spotted, investigated, and stopped a laptop farm run by an enabler in Japan, a first of its kind.
Part of a widening North Korean operation
The advisory sheds more light on a growing pattern that has developed over the months. There’s been a 420% spike in malware written to public blockchains. With a huge chunk of it originating in North Korea and Iran.
North Korea’s crypto theft was classified as a significant security threat during a G7 leaders meeting in June this year. This was after approximately $6.75 billion was found to have been stolen since 2016 by actors with North Korean links.
The recruitment lure is a recurring signature. Black Hat researcher Vangelis Stykas said this year, he had traced North Korean hackers into 1,640 companies across 57 countries, often by baiting developers with fake job offers that install malware, as Cryptopolitan reported.
financemagnates.com
coinedition.com
coinfomania.com