North Korean WaterPlum Crew Stole $10.7M in Fake-Job Crypto Raids
A joint advisory from Japanese, US, Australian and German agencies says North Korea's WaterPlum group hit 30,000 devices and took $10.7 million through bogus recruiter approaches.

Tokyo Metropolitan Police Department headquarters in Tokyo. Photo: っ via Wikimedia Commons (CC BY-SA 3.0). Source
Police and intelligence agencies in Japan, the United States, Australia and Germany say a North Korean hacking crew stole at least $10.7 million in cryptocurrency by posing as recruiters and infecting job seekers' computers with malware. The joint cybersecurity advisory, published Sept. 18, names the actor WaterPlum and puts the damage at more than 30,000 compromised devices across 100-plus countries. BleepingComputer reported the figures Sept. 19, citing the multi-agency notice.
The advisory comes from Japan's National Police Agency and National Cybersecurity Office together with the FBI, the US Department of Defense Cyber Crime Center, Australia's cyber security centre and Germany's domestic intelligence and foreign intelligence services. Germany's Federal Intelligence Service describes WaterPlum as almost certainly a state-sponsored, financially driven North Korean actor whose main goal is to loot cryptocurrency and break into financial accounts.
The method starts with a job offer that looks real. The crew approaches software developers and IT staff through social media, job boards, gig platforms and freelance marketplaces, sometimes impersonating legitimate crypto, AI or NFT companies and sometimes working through recruiting services. During interviews or coding tests, the target is told to download and run files presented as assignments or fixes for video-conferencing errors. Those files open an infection chain that pulls down further malware to spy on the machine and steal access credentials, the German service said.
The campaign ran from around December 2025 through July 2026, according to the notice. Its preferred victims were web designers, engineers and specialists in cryptocurrency, blockchain and Web3 technologies. Funds or account credentials came out of more than 7,000 crypto wallets, and the operators moved 1.7 billion yen, worth about $10.71 million, to North Korea. Cointelegraph reported the same toll Sept. 21.
The malware set behind the intrusions has names security teams already track. BleepingComputer's account lists BeaverTail, JavaScript code hidden in npm packages; InvisibleFerret, a Python-based backdoor; OtterCookie, a JavaScript remote-access trojan that also steals information; OtterCandy, which pairs OtterCookie with remote-access functions; and StoatWaffle, modular Node.js malware delivered through malicious Visual Studio Code projects whose configuration files run code once a folder is opened and trusted.
Once inside, the crew takes whatever the machine holds. Browser credentials, clipboard contents, keystrokes, private keys and seed phrases, documents and screenshots all go out the door, the report said. Access to a developer's computer can then become a path into the employer's or client's network, opening the way to intellectual property theft and espionage alongside the direct coin theft.
WaterPlum is the name governments now use for a crew the industry has tracked for years as Contagious Interview, with German officials also linking it to activity called Deceptive Development. The group hides its traffic in legitimate developer infrastructure, including GitHub and the Ethereum blockchain, and it has operated worldwide since 2022, according to the German notice.
The advisory ties the hackers directly to North Korea's remote-worker pipeline. Some WaterPlum operators double as fraudulent IT staff taking web development work for foreign clients, and investigators found both groups using the same IP addresses. Identity documents stolen in the intrusions get reused: North Korean applicants present them to land jobs under false names. The FBI and Japanese police assess that both the hackers and some of the IT workers answer to the 313 General Bureau of the Munitions Industry Department, which handles weapons research and production, the outlet noted.
Japan provided the most concrete enforcement result in the package. Authorities there identified, investigated and dismantled a North Korean IT-worker laptop farm for the first time, finding evidence that several hundred million yen in cryptocurrency had moved abroad. A separate case involved a suspected North Korean applicant to a Japanese crypto exchange who submitted a forged resume and was rejected after failing to explain the listed skills in an interview, Cointelegraph said.
The lures keep getting more convincing. Investigators found the operators using AI face-swapping software during online interviews, then switching cameras off and blaming network trouble. That detail sits inside the same advisory that urges companies to check applicants' identities, locations and qualifications, give new hires access only to systems their work requires, and keep developers from running unknown code outside a sandbox.
The pattern reached at least one prominent crypto company this summer. In July, Consensys said it had unknowingly engaged a North Korea-linked developer as a consultant, cut off access on discovery, and found no theft of assets or data, no planted code and no effect on user safety. The episode shows the hiring channel working as the advisory describes it, with the damage caught after access rather than before.
The numbers fit a longer record of North Korean coin theft. The FBI blamed North Korea for the $1.5 billion Bybit theft in February 2025, and US authorities have warned about undercover North Korean IT workers since at least 2018, Cointelegraph noted in its coverage. Against that background, the Sept. 18 notice reads as a measurement exercise as much as a warning: six agencies pooling tracing to price one crew's haul, count its victims and publish the malware catalog so hiring managers and developers can check what arrives with the next interview invite.