North Korean Hackers Infect 30,000 Devices, Target 7,000 Crypto Wallets

요약:North Korean hackers infected 30,000 devices and stole data from 7,000 crypto wallets while targeting victims across 100 countries.North Korea-linked

North Korean hackers infected 30,000 devices and stole data from 7,000 crypto wallets while targeting victims across 100 countries.

North Korea-linked hackers infected more than 30,000 devices and stole information from over 7,000 crypto wallets. Japans National Police Agency says the attacks were carried out against targets in over 100 countries from December 2025 to July 2026. The FBI and other foreign agencies aided the investigation.

The primary audience for WaterPlum (also called Contagious Interview) was IT professionals. The group targeted developers and others in the tech industry using fake job offers.

WaterPlum Uses Fake Jobs to Target Crypto Professionals

Japanese authorities say that WaterPlum reached out to job seekers via social media. It also leveraged online job sites, freelance websites, and gig-work platforms.

North Korean Hackers Infect Over 30,000 Devices, Steal Data From 7,000 Crypto Wallets

Japans National Police Agency and the FBI reported that North Korea-linked WaterPlum infected over 30,000 devices across more than 100 countries and regions from December 2025 to July 2026,…

The attackers were allegedly impersonating cryptocurrency, artificial intelligence, and NFT companies. They also pretended to be recruitment agencies to seem genuine.

Related reading: South Korea Eyes Law for Crypto Wallet Seizures.

Discover more

Compare Exchange Rates

NEWS

Choose POS Systems

Once they met, they were required to do coding tasks or technical interviews with the group. But these tasks may involve victims downloading malware.

The malicious files were found on online development platforms and code repositories. These files were then used by victims in technical assignments or software troubleshooting.

WaterPlum has been utilizing multiple malware families in these attacks. These were BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle.

In addition, the malware might create access to infected computers. It might also take passwords, screenshots, what you type on the keyboard, and clipboard data.

The attackers also attacked cryptocurrency wallet information. This comprised private keys, seed phrases, and other delicate wallet information.

In the meantime, authorities discovered that wallets controlled by WaterPlum received at least $10.71 million in cryptocurrency. The National Police Agency in Japan estimated this to be about ¥1.7 billion.

The infections impacted over 30,000 PCs in over 100 countries and regions. The primary targets were Web designers, engineers, blockchain workers, and Web3 professionals.

North Korean IT Workers Used Laptop Farms

The investigation also revealed North Korean IT workers and local supporters. The workers are said to have used a remotely controlled computer in the supporters home.

The Japanese government called these facilities “laptop farms.” These types of arrangements enabled employees to conceal their true identities when working online.

Furthermore, some employees were on virtual private servers and crowdsourcing. They reportedly operated from North Korea, China, Russia, Africa, and Southeast Asia.

The investigation also uncovered a suspected North Korean IT worker that applied to bitFlyer. In May 2025, the applicant applied for a position in engineering at the Japanese cryptocurrency exchange.

The applicant allegedly applied using someone elses identity information in the application. The person also used the recruitment website via VPN services.

Investigators noticed a few suspicious items during the interview. The applicants technical responses were unclear, even with extensive professional experience.

The applicant also refused to move to Japan and demanded that his salary be paid in cryptocurrencies. Moreover, voices of other people were allegedly heard in the interview.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

CFTC, 백악관 검토를 위해 가상자산 시장 규제 계획 제출

다음

CLARITY Act 매도세 이후 암호화폐 관련 주식 반등