VERSE PRESS

Crypto News, Global First.

North Korean Hacker Group WaterPlum Stole $10.7M in Crypto Across 100 Countries, Seven Agencies Warn

A joint advisory from law enforcement agencies in Japan, the United States, Australia, and Germany has publicly attributed a sweeping cryptocurrency theft campaign to WaterPlum, a North Korean state-sponsored hacking group that infected more than 30,000 devices worldwide between December 2025 and July 2026.

|

The group, also known by the operational alias "Contagious Interview," used fabricated job offers on social media, freelance platforms, and job boards to deliver malware to technology professionals. Once installed, the malicious software harvested login credentials for roughly 7,000 cryptocurrency wallets, ultimately transferring approximately 1.7 billion yen (around $10.71 million USD) to attacker-controlled accounts. The advisory was signed by Japan's National Police Agency (NPA) and National Cyber Office, the US FBI and Department of Defense Cyber Crime Center, and Australia's ASD and ACSC, along with Germany's BND and BfV intelligence agencies.

"WaterPlum posed as corporate headhunters recruiting information technology professionals, sending malware-infected files disguised as technical assessments to steal victims' crypto-asset account credentials," the NPA said in a statement.

How the Attack Worked

Targets received outreach that mimicked legitimate recruiting, then were asked to complete a coding test as part of the application process. Those tests contained malicious packages published to NPM, the standard software registry used by JavaScript and Node.js developers worldwide. Installing the package silently deployed one or more of five identified malware strains: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The malware searched for private key material and seed phrases (the master passwords that control self-custody crypto wallets) stored in browsers and local files.

WaterPlum operates under North Korea's 313th General Bureau, a weapons and munitions oversight body within the Workers' Party of Korea. It is a separate unit from the better-known Lazarus Group and its sub-unit TraderTraitor, though researchers describe the groups as operationally adjacent within Pyongyang's broader cyber operations rather than sharing a confirmed unified command structure.

A Fraction of a Larger Problem

The $10.7 million attributed to WaterPlum's campaign is significant on its own, but it sits inside a far larger pattern. North Korean actors stole a record $2.02 billion in cryptocurrency during 2025, a 51 percent year-over-year increase that represented roughly 59 percent of all global crypto theft that year, according to Chainalysis's report "2025 Crypto Theft Reaches $3.4 Billion."

The trajectory has continued into 2026. Two attacks alone, a $285 million breach of Drift Protocol on April 1 and a $292 million exploit of the KelpDAO LayerZero bridge on April 18, pushed North Korea's share of all crypto hack losses to 76 percent of total global theft value through April 2026, per TRM Labs research. Those two attacks represented only around 3 percent of total incident count during that period, a striking concentration that illustrates how North Korea's operations are built around a small number of extremely high-value targets rather than broad, distributed campaigns. Since 2017, attributable North Korean crypto theft now exceeds $6.75 billion cumulative, according to TRM Labs and sanctions.io.

After the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned mixing services Tornado Cash and Sinbad.io, tools used to obscure the origin of stolen funds, DPRK-linked actors shifted laundering operations almost entirely to THORChain, a permissionless cross-chain swap protocol that allows tokens to be exchanged across blockchains without a central operator. TRM Labs identified THORChain as the consistent routing choice for North Korea's largest heists. In the KelpDAO case, $175 million in ether moved through THORChain within 72 hours of the attack. An additional $75 million was frozen on the Arbitrum network. TRM Labs noted that THORChain had not blocked transactions linked to the heist.

TRM Labs and sanctions.io have also traced the downstream end of these laundering routes to over-the-counter trading desks concentrated in Southeast Asia and the Middle East. That concentration creates compliance pressure on crypto exchanges operating in those regions under Financial Action Task Force frameworks, as local platforms risk becoming unwitting exit points for stolen funds.

Why This Matters Beyond Japan

The advisory's reach is global, and its practical consequences fall unevenly. The attack vector targets the global freelance and remote tech workforce, a cohort heavily concentrated in South Asia and Southeast Asia. Developers in India, Pakistan, Bangladesh, and Sri Lanka frequently seek remote contracts with international crypto and Web3 companies through platforms like LinkedIn, Upwork, and Freelancer.com, all of which are explicitly named in the advisory as WaterPlum recruiting channels. Any developer who runs a coding test from an unverified recruiter and installs the associated NPM package is at risk, regardless of where they are located.

In Africa, Nigeria, Kenya, South Africa, Ghana, and Ethiopia have seen significant growth in peer-to-peer crypto usage and self-custody wallet adoption. Many users in these markets are unbanked or underbanked, a structural condition that drives high rates of self-custody adoption and also means that institutional warning infrastructure, including the channels through which NPA or FBI bulletins reach the public, is largely absent. Self-custody wallets, where the user holds their own private keys, are precisely what WaterPlum's malware is designed to drain.

A parallel scheme compounds the threat. North Korean workers have separately obtained employment at tech and crypto companies using false identities, routing salaries back to Pyongyang. CryptoTimes reported that a job applicant targeting Japanese crypto exchange bitFlyer claimed Malaysian identity while operating from Finland, with overlapping IP addresses tying the application to WaterPlum infrastructure.

What Comes Next

The seven-agency advisory uses a "public attribution" framework, a diplomatic tool that names state-backed actors on the record and applies reputational pressure without immediate sanctions. For crypto regulators in India, Kenya, and Nigeria, all of which have active policy debates in 2026, this advisory adds weight to arguments for mandatory wallet screening and stricter travel rule compliance for local crypto service providers. Tighter compliance requirements could, however, also restrict access for retail users in those markets, a consequence flagged by analysts at the Japan Times and CSIS as a direct trade-off policymakers will need to weigh. Developers can reduce their personal exposure immediately by verifying recruiter identities before running any provided code, auditing third-party package dependencies, and isolating test environments from machines that hold wallet access. These steps align with protective guidance issued by Australia's ACSC as part of the joint advisory.