Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
North Korean hackers steal $11 million in cryptocurrency from 30,000 devices across 100 countries
00

North Korean hackers steal $11 million in cryptocurrency from 30,000 devices across 100 countries

Sep 18, 2026

An international law enforcement coalition has exposed a massive North Korean cyber campaign, dubbed WaterPlum, which infected over 30,000 devices across 100 countries. Posing as recruiters, the hackers tricked IT professionals into downloading malware-laden coding tests, allowing them to compromise over 7,000 cryptocurrency wallets and steal up to $11 million. Authorities also dismantled a supporting network of laptop farms in Japan used by North Korean IT workers operating under false identities.

WaterPlum fake recruitment campaign

  • ▪Operators of the North Korea-linked WaterPlum hacking group posed as corporate headhunters for artificial intelligence, cryptocurrency, and non-fungible token firms on social media, job boards, and freelance marketplaces
  • ▪A North Korean hacker group known as WaterPlum, also tracked as Contagious Interview, targeted IT professionals with fake job opportunities from December 2025 to approximately July 2026.
  • ▪The WaterPlum cyber campaign, which infected more than 30,000 devices between December 2025 and July 2026, targeted web designers, software developers, engineers, and cryptocurrency and Web3 specialists across more than 100 countries and regions, including Japan

Malware infection methods

  • ▪Malware installed by WaterPlum hackers via bogus coding tests allowed WaterPlum hackers to remotely control devices, capture browser passwords, screenshots, clipboard contents, keystrokes, and identity documents
  • ▪Operators of the North Korea-linked WaterPlum campaign instructed job applicants to download files presented as coding assignments, technical assessments, or recruitment tests, which contained malicious software
  • ▪Malicious files disguised as coding assignments used in the WaterPlum campaign infected more than 30,000 devices used by IT professionals, installing remote access trojans and information stealers to gain persistent access to credentials and sensitive data

Cryptocurrency wallet theft

  • ▪WaterPlum hackers compromised more than 7,000 cryptocurrency wallets and accounts, stealing digital assets that were subsequently transferred to North Korea.
  • ▪The cryptocurrency thefts attributed to the WaterPlum campaign, which ran from December 2025 to July 2026, totaled at least 1.7 billion yen, or approximately $10.71 million to $10.9 million

North Korean IT worker operations

  • ▪North Korean IT workers living in North Korea, China, and Russia used stolen identity documents to impersonate victims and secure remote programming jobs to generate foreign currency.
  • ▪Japanese authorities shut down the country's first known laptop farm, where local helpers kept computers in their homes to allow remote North Korean workers to pose as Japanese residents.
  • ▪A suspected North Korean IT worker unsuccessfully applied for an engineering role at Japanese cryptocurrency exchange bitFlyer in May 2025 using a stolen resume.
  • ▪Japanese police dismantled a local network of supporters who provided computers, servers, identification documents, and financial accounts to facilitate North Korean IT worker operations.

International law enforcement attribution

  • ▪A joint advisory on the WaterPlum cyber campaign, released by Japan's National Police Agency and the FBI, attributed both the WaterPlum cyber actors and certain North Korean IT workers to the 313 General Bureau of the Munitions Industry Department of North Korea
  • ▪Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the United States, including the FBI and Japan's National Police Agency, issued a joint advisory on September 18, 2026.
  • ▪A joint advisory on the WaterPlum campaign, released by Japan's National Police Agency and the FBI on September 18, 2026, was issued under a framework called 'public attribution', designed to deter future cyberattacks by publicly exposing the organizations and countries involved

Debatable claims

  • ▪Public attribution of state-sponsored cyberattacks is an effective deterrent
  • ▪Remote hiring platforms should mandate biometric identity verification to prevent infiltration
  • ▪Companies should face legal penalties for unwittingly hiring sanctioned North Korean IT workers

5 sources

Theregister
North Korea's fake job interviews infected 30,000 devices
View source article
Mezha
North Korea-Linked Hackers Stole at Least $10.9 Million Through Fake Job Offers
View source article
Unn
North Korean hackers attacked IT engineers in 100 countries and stole nearly $11 million in cryptocurrency | УНН
View source article
Beincrypto
Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets
View source article
Japantimes
North Korean hackers behind crypto thefts across 100 countries, including Japan
View source article

Story comments

Loading comments…

Related entities

CybersecurityNorth Korea

Topics

Crypto privacy & surveillanceCrypto security