Police and intelligence agencies in Japan, the U.S., Australia and Germany said the group infected at least 30,000 devices across more than 100 countries.
It took funds or credentials from over 7,000 crypto wallets and moved ¥1.7 billion, around $10.71 million, to North Korea.
Japanese authorities dismantled a domestic “laptop farm” for the first time.
A North Korean crew that poses as recruiters to compromise developers has taken funds or credentials from more than 7,000 cryptocurrency wallets and moved around $10.71 million to Pyongyang, seven agencies across four countries said in a joint advisory published on September 18.
The group, which Japan’s National Police Agency calls WaterPlum and the security industry knows as Contagious Interview, infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026. Targets were web designers, engineers and specialists in crypto, blockchain and Web3 work.
It is signed by Japan’s National Police Agency and National Cybersecurity Office, the FBI and the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate’s Australian Cyber Security Centre, and Germany’s BND foreign intelligence service and BfV domestic security agency.
The NPA and the FBI assess that both WaterPlum and some of North Korea’s remote IT workers report to the 313 General Bureau of the Munitions Industry Department, which sits under the Workers’ Party central committee. The two operations also used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs, which the agencies treat as evidence the two are one operation.
Myriad: Ethereum next move: Pump to $3K or Dump to $1.5K? Click to make your prediction.
North Korea’s hacking campaign
Actors impersonate AI, crypto or NFT companies, approach developers through social media, job boards and freelance marketplaces, then set a technical interview or coding task. Candidates are told to download files from developer platforms, either to finish the assignment or to fix an apparent fault in the video call. The advisory names five malware families carried in those packages, among them BeaverTail, InvisibleFerret and StoatWaffle, the last of which hides in blockchain-themed repositories.
The advisory also logs what investigators observed of the crew itself. Members used AI face-swapping software in interviews before cutting video and asking the candidate to do the same, blaming the connection. They practised Japanese pronunciation with text-to-speech tools, worked consistently on free machine-translation and AI tiers, and on holidays celebrated in North Korea played games and watched soccer videos instead of running their usual operations.
Japanese authorities also identified and dismantled a laptop farm run by a domestic enabler, the first such case in the country, finding evidence that several hundred million yen in crypto had moved abroad. A laptop farm is usually an enabler’s home, where work computers are run remotely by IT workers in North Korea, China or Russia.
A Japanese crypto exchange turned away an applicant in May 2025 whose résumé claimed implausibly broad skills and whose English did not match the record. Other tells include refusing to meet in person, asking to be paid in crypto, and glancing repeatedly at a second screen.
The theft sits inside a far larger campaign. CertiK attributed 60% of all crypto theft losses in 2025, some $2.06 billion, to North Korea-linked groups, and April’s $285 million Drift Protocol hack followed six months of attackers posing as a quantitative trading firm.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.