Overview
- Law enforcement and intelligence organizations from Japan, the U.S., Australia, and Germany reported that the cyber group compromised at least 30,000 devices worldwide.
- The group accessed over 7,000 cryptocurrency wallets, transferring approximately ¥1.7 billion, equivalent to $10.71 million, to North Korea.
- For the first time, Japanese authorities have shut down a domestic "laptop farm" involved in this scheme.
A North Korean cyber operation, known as WaterPlum by Japan's National Police Agency and referred to as Contagious Interview in the security sector, has reportedly infiltrated over 7,000 cryptocurrency wallets, successfully transferring around $10.71 million to Pyongyang, according to a joint advisory released by seven agencies across four nations on September 18.
The group infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026, targeting web designers, engineers, and professionals in the fields of cryptocurrency, blockchain, and Web3.
North Korean cyber group “WaterPlum” is compromising job seekers’ computer networks, harvesting sensitive data, and stealing cryptocurrency - targeting IT professionals in Japan, U.S., Europe, and beyond. Read our advisory with @FBI and @NPA_KOHO at https://t.co/ugVY5mmo6y pic.twitter.com/Q74qeXWQoP
— DoD Cyber Crime Center (DC3) (@DC3Forensics) September 18, 2026
The advisory is co-signed by Japan's National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, and Germany's BND and BfV agencies.
Both the NPA and the FBI believe that WaterPlum and some of North Korea's remote IT workers are linked to the 313 General Bureau of the Munitions Industry Department, which operates under the Workers' Party central committee. The two operations utilized identical IP addresses to access laptop farms, leverage crowdsourcing services, and apply for jobs, indicating a connection between them.
Details of the Hacking Campaign
The hackers impersonate companies in the AI, crypto, or NFT sectors, reaching out to developers via social media, job boards, and freelance platforms to schedule technical interviews or coding tasks. Applicants are instructed to download files from developer sites to complete the tasks or to resolve supposed issues with the video call. The advisory lists five types of malware associated with these downloads, including BeaverTail, InvisibleFerret, and StoatWaffle, the latter of which is camouflaged within blockchain-related repositories.
Investigators have also provided insights into the group's methods. Members used AI face-swapping technology during interviews, asking candidates to mimic the process while citing connection issues. They practiced Japanese pronunciation using text-to-speech software and consistently engaged with free machine translation and AI tools, even taking breaks during North Korean holidays to play games and watch soccer instead of conducting operations.
In a significant development, Japanese authorities uncovered and dismantled a laptop farm operated by a local accomplice, marking the first instance of such a case in Japan. Evidence revealed that hundreds of millions of yen in cryptocurrency had been transferred overseas. A domestic crypto exchange had previously rejected an applicant in May 2025 due to an unrealistic skill set and mismatched English proficiency. Other red flags included the candidate's refusal to meet in person, requests for crypto payments, and frequent glances at a secondary screen.
This incident is part of a broader campaign. CertiK reported that North Korean-linked groups accounted for 60% of all cryptocurrency theft losses in 2025, totaling around $2.06 billion. This follows the $285 million hack of the Drift Protocol in April, which occurred after six months of attackers posing as a quantitative trading firm.
