Crypto news report · source clearly identified
North Korean WaterPlum group steals data from over 7,000 crypto wallets, Japan reports
North Korea linked hacking group WaterPlum has compromised more than 30,000 devices across over 100 countries and regions, stealing information from more than 7,000 cryptocurrency wallets while targeting developers through fake recruitment campaigns.

Japan’s National Police Agency, together with U.S., Australian and German authorities, disclosed that the North Korean‑linked hacking group WaterPlum infected more than 30,000 computers in over 100 countries between late 2025 and mid‑2026. The campaign stole data from more than 7,000 cryptocurrency wallets and generated at least 1.7 billion yen (about $10.7 million) in illicit proceeds.
Attack vectors and malware used
WaterPlum posed as AI, crypto and NFT companies on social media, job sites and freelance platforms. Victims were asked to download malicious files during interview tasks or coding tests. The malware payloads included variants named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, often delivered via compromised NPM packages. Once installed, the tools created backdoors, captured keystrokes, screenshots, clipboard data and extracted private keys, seed phrases and identity documents.
Fake recruitment schemes
The group targeted developers, web designers and engineers with seemingly attractive remote jobs. Applicants were instructed to run code to “diagnose” video‑conferencing software or complete coding assignments, which actually installed the malware. A separate attempt to secure an engineering role at Japanese exchange bitFlyer was intercepted after the applicant used a false identity and VPN/proxy services.
Domestic laptop farms
Japanese investigators dismantled a domestic “laptop farm” used by North Korean IT workers. Local facilitators housed computers while remote operators controlled them, using forged identity documents to apply for contracts. Payments were routed through bank accounts of the facilitators before being transferred overseas. Similar operations have been prosecuted in the United States, resulting in prison sentences and cryptocurrency forfeitures.
International coordination
The investigation involved Japan’s National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center and law‑enforcement agencies in Australia and Germany. All parties linked WaterPlum and certain North Korean IT workers to Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department.
Advice for companies
Authorities urged firms to verify applicants’ locations, qualifications and payment preferences, especially when candidates insist on remote work or cryptocurrency salaries. Technical skill assessments and IP‑address checks were recommended to detect spoofed identities.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- September 18, 2026, 2:38 PM
- Original headline
- North Korean hackers stole 7,000 crypto wallet records, Japan says