WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets

WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets

North Korean hackers posed as tech recruiters to compromise developers and siphon roughly $10.71 million in crypto assets over a seven-month campaign

A North Korean hacking operation known as WaterPlum compromised more than 30,000 devices worldwide and extracted data from over 7,000 cryptocurrency wallets, funneling at least 1.7 billion Japanese yen, roughly $10.71 million, into wallets tied to Pyongyang’s interests.

The campaign, which ran from December 2025 through July 2026, targeted a specific demographic: IT professionals and software developers. The attackers posed as recruiters offering jobs at companies in AI, cryptocurrency, and NFTs.

How the operation worked

WaterPlum, also tracked under the name Contagious Interview, exploited something every developer does: apply for jobs. The hackers created fake recruiter profiles on social media and employment platforms, then invited targets to participate in fraudulent job interviews or complete coding tasks that were laced with malware.

Advertisement

Once a victim engaged, a suite of custom malware did the heavy lifting. The toolbox included strains called BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The programs were designed to extract sensitive data, with a particular focus on crypto wallet credentials and private keys.

On September 18, 2026, a coalition of law enforcement agencies formally attributed the campaign to the 313th Bureau of North Korea’s Munitions Industry Department. That joint statement came from Japan’s National Police Agency and the US FBI, among others. The 313th Bureau is a known entity within North Korea’s weapons development infrastructure.

Part of a much bigger pattern

The country’s most notorious cyber unit, the Lazarus Group, was behind the $1.4 billion Bybit hack earlier in 2025, which remains the largest single crypto heist on record. Pyongyang-linked hackers have also been caught infiltrating companies by getting hired as remote IT workers, collecting paychecks while simultaneously exfiltrating sensitive data.

The WaterPlum campaign also utilized facilitated networks within Japan to expand its operational footprint, suggesting a level of on-the-ground coordination that goes beyond purely remote hacking.

What this means for the crypto industry

The breadth of the campaign, 30,000 infected devices across multiple countries, suggests that WaterPlum cast a wide net rather than targeting specific high-value individuals. In aggregate, thousands of smaller wallets added up to an eight-figure haul.

The formal attribution by the FBI and Japanese authorities also carries diplomatic weight. Joint public attributions are relatively rare and typically signal that law enforcement agencies have high confidence in their findings.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets
WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets

North Korean hackers posed as tech recruiters to compromise developers and siphon roughly $10.71 million in crypto assets over a seven-month campaign

A North Korean hacking operation known as WaterPlum compromised more than 30,000 devices worldwide and extracted data from over 7,000 cryptocurrency wallets, funneling at least 1.7 billion Japanese yen, roughly $10.71 million, into wallets tied to Pyongyang’s interests.

The campaign, which ran from December 2025 through July 2026, targeted a specific demographic: IT professionals and software developers. The attackers posed as recruiters offering jobs at companies in AI, cryptocurrency, and NFTs.

How the operation worked

WaterPlum, also tracked under the name Contagious Interview, exploited something every developer does: apply for jobs. The hackers created fake recruiter profiles on social media and employment platforms, then invited targets to participate in fraudulent job interviews or complete coding tasks that were laced with malware.

Advertisement

Once a victim engaged, a suite of custom malware did the heavy lifting. The toolbox included strains called BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The programs were designed to extract sensitive data, with a particular focus on crypto wallet credentials and private keys.

On September 18, 2026, a coalition of law enforcement agencies formally attributed the campaign to the 313th Bureau of North Korea’s Munitions Industry Department. That joint statement came from Japan’s National Police Agency and the US FBI, among others. The 313th Bureau is a known entity within North Korea’s weapons development infrastructure.

Part of a much bigger pattern

The country’s most notorious cyber unit, the Lazarus Group, was behind the $1.4 billion Bybit hack earlier in 2025, which remains the largest single crypto heist on record. Pyongyang-linked hackers have also been caught infiltrating companies by getting hired as remote IT workers, collecting paychecks while simultaneously exfiltrating sensitive data.

The WaterPlum campaign also utilized facilitated networks within Japan to expand its operational footprint, suggesting a level of on-the-ground coordination that goes beyond purely remote hacking.

What this means for the crypto industry

The breadth of the campaign, 30,000 infected devices across multiple countries, suggests that WaterPlum cast a wide net rather than targeting specific high-value individuals. In aggregate, thousands of smaller wallets added up to an eight-figure haul.

The formal attribution by the FBI and Japanese authorities also carries diplomatic weight. Joint public attributions are relatively rare and typically signal that law enforcement agencies have high confidence in their findings.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.