North Korea-Linked Group Infected More Than 30,000 Devices: How Crypto Wallets Were Targeted?
According to the National Police Agency of Japan and the FBI, the North Korea-linked WaterPlum infected more than 30,000 devices across over 100 countries and regions, stealing data from more than 7,000 crypto wallets.
The campaign targeted job seekers through fake employment opportunities. Attackers posed as recruiters for crypto, AI, and NFT companies, asking candidates to run malicious software.
WaterPlum reportedly conducted this campaign between December 2025 and July 2026.
At least $10.71 million worth of crypto assets were transferred to wallets controlled by WaterPlum.
Fake job postings were at the center of the attack
As part of the investigation, Japanese police dismantled a local laptop farm, identified for the first time, which reportedly supported North Korean IT workers.
Authorities also revealed that a suspicious North Korean IT worker applied for an engineering position at the Japanese crypto exchange bitFlyer in May 2025, but was not hired.
