North Korean Cyber Activities Unveiled
In a recent coordinated report released on September 18, security agencies from four nations have unveiled the activities of a North Korean group known for deceitfully posing as technology recruiters to exploit software developers. This rogue crew is suspected of pilfering from over 7,000 cryptocurrency wallets, channeling approximately $10.71 million back to Pyongyang.
Identification of the Group
Designated as WaterPlum by Japan’s National Police Agency (NPA) and recognized in cybersecurity circles as Contagious Interview, this syndicate has reportedly compromised around 30,000 devices across more than 100 countries between December 2025 and July 2026. The targeted individuals include freelancers and professionals specializing in web development, blockchain technology, and cryptocurrency-related fields.
Joint Alert from Security Agencies
The joint alert comes from multiple organizations: Japan’s NPA, the FBI, the U.S. Department of Defense Cyber Crime Center, Australia’s Cyber Security Centre, and Germany’s domestic security service (BfV), along with its foreign intelligence agency (BND). These organizations believe that WaterPlum, along with some remote IT personnel from North Korea, likely operate under the auspices of the 313 General Bureau of the Munitions Industry Department, which is affiliated with the ruling Workers’ Party.
Modus Operandi of the Hackers
Investigation reports suggest that the hackers impersonate legitimate companies in the artificial intelligence, cryptocurrency, or non-fungible token (NFT) sectors, making contact with potential victims via social media, job platforms, and freelance sites. These con artists then arrange technical interviews or coding tasks, compelling candidates to download potentially malicious files under the pretext of completing the assignment or resolving an issue with the video interview connection.
The malware species identified in these operations includes BeaverTail, InvisibleFerret, and StoatWaffle, found hidden within blockchain-themed repositories. Agencies have also noted that the individuals within the group utilized AI software to swap their faces during interviews and fabricated video clips, instructing candidates to mimic this practice while blaming connectivity issues.
Significant Breakthroughs and Encounters
Moreover, the NPA has reported the dismantling of a domestic laptop farm tied to these activities, marking a significant breakthrough as it represents the first recorded instance of such operations being uncovered in Japan. Evidence has been found showing that hundreds of millions of yen worth of cryptocurrency had been transmitted offshore from this farm, typically run from the residence of an enabler whose role includes directing North Korean IT workers.
A notable encounter occurred in May 2025 when a Japanese crypto exchange rejected an applicant who claimed an implausibly extensive skill set and displayed poor English proficiency inconsistent with their résumé. Other red flags included avoidance of in-person meetings, requests for payment in cryptocurrency, and frequent glances toward a secondary screen during discussions.
Wider Implications of Cryptocurrency Theft
The ongoing theft of cryptocurrencies is part of a much larger scheme. A report by CertiK revealed that North Korea-linked groups were responsible for a staggering 60% of all crypto thefts in 2025, tallying approximately $2.06 billion, with the infamous $285 million hack of Drift Protocol in April being a notable incident that followed months of scamming efforts disguised as a quantitative trading firm.