Investigation into WaterPlum Hacking Group
A recent investigation revealed that the hacking group known as WaterPlum, which is associated with North Korea, has infiltrated more than 30,000 devices globally and targeted over 7,000 cryptocurrency wallets. According to a report from Japan’s National Police Agency, the group’s hacking initiatives were unveiled through a collaborative effort involving the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, and law enforcement agencies from Australia and Germany. The inquiry, disclosed on September 18, highlighted the attack methods employed by WaterPlum, suggesting connections to North Korean IT professionals operating under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department.
Scope and Impact of the Infiltration
The scope of the infiltration spanned across more than 100 nations, including Japan, with significant impact on professionals in web development, engineering, and the cryptocurrency and blockchain sectors. It is estimated that these attacks occurred between December 2025 and July 2026, coinciding with a reported loss of approximately 1.7 billion yen (around $10.7 million) in stolen funds being funneled into wallets controlled by the hackers.
Recruitment Tactics and Malware
WaterPlum’s recruitment tactics, dubbed “Contagious Interview”, involved deceptive job offers aimed at software developers and IT staff. These operations were carried out through social media, online job platforms, and freelance marketplaces, where potential victims were approached under the guise of legitimate companies in sectors like artificial intelligence and cryptocurrency. Candidates were often instructed to download harmful software during technical assessments, mistaking it for essential tools needed for workshops or coding evaluations.
The malware utilized by WaterPlum included various types such as BeaverTail and OtterCookie, hidden within compromised code libraries. Once a system was breached, the attackers could establish backdoor access, extracting sensitive data including browser credentials, keystrokes, and cryptocurrency wallet security information like private keys and seed phrases.
Surveillance and Global Operations
This surveillance on recruitment strategies highlights the innovative yet pernicious methods deployed by North Korean cybercriminals over the past seven years, as previously recorded by security researchers. Authorities noted Japan’s first identified ‘laptop farm’ linked to these hackers, where local facilitators would maintain repossessed computers while North Korean agents operated them remotely, often using stolen identities for fraudulent contracts.
The investigation also noted that hackers were able to digitally obscure their locations, with some working directly from North Korea, while others were stationed in China, Russia, and parts of Africa and Southeast Asia. This global web of deceit mirrors prosecution cases in the U.S., where individuals facilitating similar operations have faced prison time for enabling North Korean remote work.
Recent Recruitment Attempts and Recommendations
In a separate incident in May 2025, Japanese authorities uncovered an attempted recruitment at cryptocurrency exchange bitFlyer by an individual believed to have links to North Korea, who applied using a fictitious identity and circumvented detection via VPN and proxy services. Despite claiming to be Malaysian residing in Finland and demonstrating fabricated qualifications, the application raised suspicions and the candidate was not hired.
These developments have prompted Japanese authorities to advise businesses on thorough vetting of applicants, especially those requesting remote positions or cryptocurrency payments, emphasizing the importance of validating claimed experience and geographical information. The critical interlink between WaterPlum’s cyber operations and the broader network of North Korean IT workers raises concerns about future cybersecurity threats in both the crypto space and beyond.