Japan and Allies Attribute Global Hacking Campaign to North Korea‑Linked 'WaterPlum', Say 30,000 Devices Compromised
Japan and allied cyber agencies on Friday publicly attributed a global hacking campaign to a North Korea-linked group they said compromised at least 30,000 devices in more than 100 countries and stole funds or credentials from more than 7,000 cryptocurrency wallets. The victims were lured in through fake job offers in artificial intelligence, crypto and nonfungible token businesses, with the operation aimed at developers and other IT workers.
In a joint advisory dated Sept. 18, Japan’s National Police Agency and National Cybersecurity Office, together with the FBI, the U.S. Defense Cyber Crime Center, Australia’s Australian Signals Directorate and Australian Cyber Security Centre, and Germany’s Federal Intelligence Service and Federal Office for the Protection of the Constitution, said the activity was carried out by a group Japan calls WaterPlum, also known as Contagious Interview. The agencies said the attackers posed as recruiters on social media, job sites, freelance marketplaces and during technical interviews, then persuaded targets to download or run malicious files as part of supposed hiring tests. The campaign used booby-trapped NPM packages, a software code library system widely used by developers, and malicious Visual Studio Code projects, including abuse of the editor’s tasks.json autorun feature, to install malware.
The advisory said the activity ran roughly from December 2025 through July 2026. “WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,” it said. Japanese authorities said the actors transferred at least 1.7 billion yen, about $10.7 million, in crypto assets to wallets controlled by North Korea. Japan’s NPA and the FBI said they assess WaterPlum actors, along with some North Korean IT workers, operate under the 313 General Bureau of the Munitions Industry Department of the Workers’ Party of Korea.
Japan also said it had, for the first time in the country, identified, investigated and dismantled a domestic laptop farm tied to the case. Authorities described the setup as part of an enabling network used in connection with the operation and said they obtained evidence that several hundred million yen had been sent abroad.
North Korea-linked groups have for years been accused by Japan, the United States and other governments of stealing cryptocurrency to generate foreign currency for the regime. Earlier cases included the 2022 theft from Ronin, the network tied to Axie Infinity, widely reported at about $620 million, and a later joint FBI-NPA attribution linking North Korean actors to the $308 million theft from Bitcoin.DMM.com. What makes the WaterPlum case stand out is less the size of the losses than the method: rather than focusing only on exchanges or crypto bridges, the campaign targeted individual developers, freelancers, contractors and engineering teams through the tools they use every day.
According to the advisory, the malware was used to steal browser-stored login data as well as wallet seed phrases and private keys, the information needed to control crypto holdings. Investigators also said they observed the use of remote-access trojans, info-stealers, virtual private server infrastructure, laptop farms and AI face-swapping during interviews. The agencies warned that paying North Korean IT workers or knowingly facilitating such schemes may violate domestic law and international sanctions. They urged companies and individuals not to run untrusted code on machines that hold wallet data, to use sandboxes or virtual machines for testing, to enable Visual Studio Code’s Restricted Mode and review .vscode/tasks.json files, and to deploy endpoint detection tools. They also warned that even if malware is removed, victims should assume data may already have been stolen.