Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

North Korea-Linked WaterPlum Used Fake Jobs to Steal Crypto, NPA Says

Japan’s NPA says WaterPlum used fake job offers and coding tasks to compromise IT workers, exposing crypto wallets and private keys across multiple countries.

Written By Isha Chavda
Edited by Shubham Soni
Published 34 minutes ago
Make The Crypto Times preferred on GoogleGoogle
North Korea-Linked WaterPlum Used Fake Jobs to Steal Crypto, NPA Says

Key Highlights

  • Japan’s National Police Agency (NPA) says WaterPlum targeted IT professionals through fake recruitment offers and technical assignments.
  • The group infected more than 30,000 devices across over 100 countries between December 2025 and July 2026.
  • Investigators identified information linked to more than 7,000 cryptocurrency wallets, with at least ¥1.7 billion in crypto transferred to wallets controlled by the group.

Japan’s National Police Agency (NPA) has detailed how the North Korea-linked cyber group WaterPlum, also known as Contagious Interview, targeted IT professionals through fake recruitment processes and malicious coding assignments.

According to an official press release published Friday, the NPA said WaterPlum targeted software developers and other technical workers in Japan, the United States, Europe and other regions. The investigation involved the U.S. Federal Bureau of Investigation (FBI), the U.S. Department of Defense Cyber Crime Center, Australian agencies and German authorities.

The NPA said WaterPlum infected more than 30,000 devices across more than 100 countries and regions between December 2025 and July 2026. Investigators identified information linked to more than 7,000 cryptocurrency wallets, while at least ¥1.7 billion in cryptocurrency was transferred to wallets controlled by the group.

Fake recruitment used to deliver Malware

According to the NPA, WaterPlum approached IT workers through social media, job websites, freelance platforms and other recruitment channels. Attackers allegedly posed as recruiters or representatives of companies working in areas including artificial intelligence, cryptocurrency and NFTs.

Applicants were then asked to participate in technical interviews or complete coding assignments. In some cases, they were instructed to download development files or execute code while troubleshooting software or completing programming tasks.

The NPA said malicious code was embedded in some of those files and projects.

Investigators linked the campaign to malware including BeaverTail, InvisibleFerret and OtterCookie, which could provide remote access and collect information from compromised devices.

Attackers sought wallet data and private keys

Once a device was compromised, attackers could access information stored on the computer.

The NPA said the stolen information included:

  • Browser-stored credentials
  • Clipboard data
  • Keystrokes and screenshots
  • Cryptocurrency wallet information
  • Private keys and seed phrases
  • Identity documents and other files

The NPA also reported that cryptocurrency was subsequently transferred to wallets controlled by WaterPlum.

The NPA’s findings show that the campaign involved not only credential theft but also attempts to obtain information that could provide access to digital assets.

North Korean IT workers used false identities

The investigation also uncovered a separate but related operation involving North Korean IT workers who obtained overseas employment under false identities. According to the NPA and FBI, some workers used intermediaries and remote-access infrastructure to perform programming and web-development jobs for companies in Japan and other countries.

Japanese investigators identified a “laptop farm” where computers located at a local intermediary’s residence were remotely operated by North Korean IT workers. The setup allowed workers to perform jobs while obscuring their actual locations. Investigators also identified the use of virtual private servers and other remote-access infrastructure.

The NPA said related investigations found that several hundred million yen had been transferred overseas through these IT-worker activities.

bitFlyer case shows recruitment warning signs

The NPA also disclosed a 2025 recruitment case involving Japanese cryptocurrency exchange bitFlyer.

An applicant seeking an engineering position allegedly used a resume that investigators later assessed as containing a false identity. The applicant claimed to be Malaysian and living in Finland while using multiple VPN services during the recruitment process.

According to the NPA, investigators noticed inconsistencies during the online interview, including differences between the applicant’s spoken English and the background listed on the resume. The applicant also reportedly gave vague answers to technical questions, repeatedly looked at another monitor, and had other voices audible in the background.

The applicant reportedly resisted relocating to Japan and requested payment in cryptocurrency. bitFlyer did not hire the applicant, and the NPA said the incident did not result in damage to the exchange.

Japanese reporting later identified overlapping IP addresses between the applicant, North Korean IT-worker activity, and WaterPlum-related infrastructure.

NPA links the activities to North Korea’s 313th Bureau

The NPA and FBI said their investigation identified infrastructure and other connections between WaterPlum’s cyber activity and operations involving North Korean IT workers.

The agencies assess that WaterPlum and some of the related IT-worker activity were operating under the direction of North Korea’s 313th Bureau of the Workers’ Party of Korea.

The two activities served different purposes. WaterPlum’s campaign focused on compromising devices and obtaining cryptocurrency and sensitive information, while the IT-worker operation involved obtaining overseas employment and generating foreign currency.

The agencies’ attribution is an investigative assessment rather than a court finding.

NPA warns companies about recruitment and code risks

The NPA said companies can face security risks even when they do not knowingly hire North Korean IT workers. Workers using false identities may gain access to source code, credentials, internal systems and other sensitive information.

The agency recommended verifying applicants’ identities, employment histories, technical qualifications and stated locations before granting access to company systems.

Companies were also advised to limit contractor access to the systems and information required for their work.

The NPA separately warned against running unfamiliar code on computers containing sensitive information or cryptocurrency assets. Where code needs to be tested, investigators recommended using isolated environments such as virtual machines.

For unfamiliar VS Code projects, the agency recommends using Restricted Mode and reviewing configuration files such as .vscode/tasks.json before allowing code to run.

The guidance is particularly relevant to technology and crypto companies whose developers or contractors may have access to private keys, source code, cloud infrastructure, and wallet-related systems.

Earlier North Korean campaigns also targeted crypto

The WaterPlum investigation comes alongside other cases involving North Korea-linked groups and cryptocurrency.

In September, Arkham data covered wallets linked to the Lazarus Group moving more than $30 million through Hyperliquid’s HyperUnit infrastructure. The funds were reportedly converted from Bitcoin into Ethereum and Solana before being routed across multiple networks and exchanges.

A separate July 2026 report covered activity attributed to BlueNoroff, another North Korea-linked group. Attackers reportedly used fake Zoom meeting invitations sent through trusted Telegram contacts to distribute malware.

These cases involve different groups and techniques but provide broader context for the methods North Korea-linked actors have used to target cryptocurrency and technology workers.

Also Read: Nostra Halts Starknet Money Market After $3.5M NSTR Oracle Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto HackJapanNorth Korea
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

XRP Price Jumps Nearly 7% to $1.38 as Whale Activity Hits Six-Month High
XRP Price Jumps Nearly 7% to $1.38 as Whale Activity Hits Six-Month High
Why Is Ethereum Price Up Today? ETH Jumps 4.5% Toward $2,600
Why Is Ethereum Price Up Today? ETH Jumps 4.5% Toward $2,600
Bitcoin Reclaims $80K as Crypto Markets Recover From CLARITY Act Blow
Bitcoin Reclaims $80K as Crypto Markets Recover From CLARITY Act Blow
Hyperliquid Price Surges 11% as HYPE Hits New All-Time High Above $90
Hyperliquid Price Surges 11% as HYPE Hits New All-Time High Above $90
Crypto Stocks ABTC, MSTR, COIN Surge as Bitcoin Reclaims $80K
Crypto Stocks ABTC, MSTR, COIN Surge as Bitcoin Reclaims $80K

Find Us on Socials

You may also like

Coinbase Files to Expand U.S. Derivatives Into Single-Stock Perpetuals

Coinbase Files to Expand U.S. Derivatives Into Single-Stock Perpetuals

The Bybit logo alongside a glowing futuristic cube displaying stock tickers like NVDA and TSLA.

Bybit Launches 24/7 Perp Options on SpaceX and Nvidia Stock Perpetuals

Nina Power's London Flat Now in Hands of Reform UK Donor Ben Delo After £300k Libel Loan

Nina Power’s London Flat Now in Hands of Reform UK Donor Ben Delo After £300k Libel Loan

Sam Altman, CEO of OpenAI

Sam Altman’s World Adds a Financial Super App for Stablecoins and Crypto Payments

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information