North Korean Hackers Behind Crypto Thefts Across 100 Countries, Including Japan
A North Korea-linked hacking group allegedly compromised more than 30,000 devices by disguising malware as job opportunities and coding tests.
Authorities from Japan, the United States, Australia and Germany have publicly attributed a global cyber campaign to a North Korean group known as WaterPlum, also called Contagious Interview. The group allegedly infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, compromising information from more than 7,000 cryptocurrency wallets and transferring at least 1.7 billion Japanese yen in crypto assets to North Korea.
A job interview can be stressful enough without wondering whether the person offering you the job is actually a hacker.
But that is precisely the type of operation authorities say was used by a North Korea-linked cyber group in a campaign that reached victims across more than 100 countries.
The group, known as WaterPlum and commonly referred to as Contagious Interview, targeted software developers, engineers, web designers and cryptocurrency professionals by pretending to be recruiters or representatives of legitimate technology companies.
Japanese authorities said the campaign included victims in Japan, while the FBI and other international agencies helped investigate the operation.
More Than 30,000 Devices Compromised
According to the joint advisory, WaterPlum compromised at least 30,000 computers between around December 2025 and July 2026.
The victims were spread across more than 100 countries and regions, including Japan and the United States. More than 7,000 cryptocurrency wallets were affected through stolen credentials or transferred funds.
Authorities said at least 1.7 billion Japanese yen, equivalent to about $10.71 million, in cryptocurrency was transferred to wallets controlled by the group and ultimately attributed to North Korea.
The Attack Started With Fake Jobs
One of the most striking aspects of the operation was its use of employment opportunities as the initial point of attack.
Attackers posed as recruiters or companies working in artificial intelligence, cryptocurrency and non-fungible tokens. They contacted potential victims through social media, job websites, freelance platforms and other recruitment services.
Once communication had been established, victims could be asked to complete a programming assignment or technical assessment. The malicious files were presented as part of the recruitment process.
Instead of simply testing the candidate's programming skills, however, the files could provide attackers with a path into the victim's computer.
Why Developers Were Targeted
Developers and technology professionals can hold valuable information on their computers, particularly when they work with cryptocurrency, blockchain infrastructure or software projects.
A compromised developer machine can potentially expose browser credentials, cryptocurrency information, source code and other sensitive material. The authorities' advisory warns that access obtained through an individual can also become a pathway into a company.
That makes the attack different from a conventional phishing campaign aimed at stealing one password. The initial victim can become the entry point to a much wider digital environment.
The Crypto Theft
Cryptocurrency appears to have been one of the main financial targets.
Investigators said WaterPlum obtained information associated with more than 7,000 crypto wallets. The group then transferred at least 1.7 billion yen worth of cryptocurrency to wallets it controlled.
The scale illustrates why cryptocurrency remains attractive to cybercriminal organizations: stolen digital assets can potentially be moved across borders without using traditional banking channels.
Japan Was Among the Targets
Japan played a significant role in uncovering the campaign.
Japan's National Police Agency worked with the country's National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center and agencies in Australia and Germany to investigate the operation.
Japanese authorities also identified and dismantled a so-called laptop farm operated by an intermediary in Japan. Such arrangements can allow North Korean IT workers to remotely operate computers located in another country while concealing their actual location.
Authorities said evidence from the Japanese investigation showed that several hundred million yen in cryptocurrency was transferred to locations outside Japan.
The Connection to North Korean IT Workers
The international advisory also highlights another part of the North Korean cyber ecosystem: IT workers who obtain remote employment using false identities.
Japanese and U.S. authorities assess that WaterPlum operators and some North Korean IT workers operate under the direction of the 313 General Bureau of the Munitions Industry Department of the Workers' Party of Korea's Central Committee.
The two activities can create overlapping risks. A person who gains legitimate employment inside a technology company can potentially obtain access to corporate systems, sensitive information or financial resources.
A Warning for Companies
The campaign creates a difficult security problem for companies because traditional cybersecurity defenses may not be enough when the attack begins with a legitimate-looking recruitment conversation.
Companies increasingly hire remote workers and contractors through online platforms. That creates opportunities for international talent, but it also makes identity verification and access control more important.
Japanese and U.S. authorities recommend stronger verification of applicants, including checking claimed qualifications and identities and paying attention to unusual requests involving cryptocurrency payments or another person's payment account.
Why the Campaign Matters Beyond Crypto
The theft of cryptocurrency is only one part of the story.
Once attackers compromise a developer's computer, they may gain access to information unrelated to the original financial target. Corporate credentials, source code, documents and other sensitive information could potentially be exposed.
Authorities therefore view these operations as part of a wider effort to generate revenue for North Korea while also creating opportunities for access to foreign technology and organizations.
The New Cybersecurity Reality
WaterPlum's campaign demonstrates how cyberattacks are increasingly blending social engineering, employment fraud, malware and cryptocurrency theft into a single operation.
The attack does not require a victim to click a suspicious advertisement or open an obviously malicious email. The victim may instead believe they are completing a legitimate interview for a potentially valuable job.
That makes trust itself part of the attack surface.
The most dangerous part of this campaign may not be the malware itself. It is the fact that the attack begins with something millions of professionals actively want: a job. As cybercriminals become better at turning trust into an entry point, verifying who is behind an opportunity could become as important as securing the device itself.
Technology, cybersecurity and the forces reshaping the digital world.
