North Korea's WaterPlum Crypto Thefts Attributed

摘要:Japans National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts

Japans National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cyber group also known as Contagious Interview. The joint advisory says the group infected at least 30,000 machines across more than 100 countries, stole around 7,000 crypto wallet records and moved at least about 1.7 billion yen in digital assets, according to the official announcement.

A Coordinated Four-Nation Attribution

The statement was issued jointly by Japan, the United States, Australia and Germany, and places WaterPlum under the command of the 313th General Bureau of the Korean Workers‘ Party Central Committee’s Military Industry Department. The NPA said the findings came from information supplied by private companies and from investigations by its Kanto Regional Police Bureau cyber division and prefectural police. By naming the group and its command structure, the four governments are warning IT engineers and companies worldwide to harden their defenses against a campaign that has run for months.

The Scale of the WaterPlum Campaign

WaterPlum targets IT engineers with fake job offers, a technique the advisory ties to the Contagious Interview scheme, to deliver malware and drain crypto wallets. The NPA estimates at least 30,000 machines were infected across more than 100 countries and regions including Japan, with around 7,000 wallet records stolen and at least about 1.7 billion yen — roughly $11.5 million — moved in crypto assets. The disclosure fits a longer pattern of North Korean cyber operations that have already compromised 1,640 companies across 57 countries.

Discover more

financial

Economics

News

Laptop Farms and North Korean IT Workers

The advisory also details how North Korean IT workers earn foreign currency for the regime. Japanese police said they identified for the first time domestic “laptop farms” remotely operated by North Korean IT workers, which sent hundreds of millions of yen overseas, including crypto. A Japanese crypto exchange separately reported receiving job applications from North Korean IT workers for engineer roles and detected the activity during interviews. The warning follows other recent North Korean crypto activity, including Lazarus-linked Bitcoin sales tracked on Hyperliquid.

Why the Attribution Matters

The joint announcement marks a rare, coordinated public naming of a North Korean cyber group by four governments, and it frames crypto theft as a national-security and economic threat rather than isolated crime. For exchanges, wallets and developers, the practical takeaway is to treat unsolicited job offers and recruitment messages as a security risk, and to screen remote hires carefully. The NPA urged IT engineers and private companies to review the advisory and strengthen their security measures.

With over five years of experience in crypto, blockchain, and tech content, Ishtiyaq makes complex topics easy to understand. He simplifies blockchain and digital currency concepts for a wide audience, ensuring that beginners and experts alike can grasp key ideas. His clear and engaging writing helps readers stay informed about the latest trends, developments, and innovations in the crypto space. Whether explaining blockchain technology, digital assets, or DeFi, Ishtiyaq breaks down complicated ideas into simple, digestible content. His goal is to help people navigate the fast-changing world of cryptocurrency with confidence, clarity, and a deeper understanding.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

伊朗利用加密货币资助IRGC受限 美国财政部再制裁加密交易所

下一篇

WikiBit交易所跑路風險榜第31期CoinW:詐騙洗錢23億、扣下52萬美元賬戶、被韓國和土耳其封殺