Key Highlights
- Japan’s National Police Agency (NPA) says WaterPlum targeted IT professionals through fake recruitment offers and technical assignments.
- The group infected more than 30,000 devices across over 100 countries between December 2025 and July 2026.
- Investigators identified information linked to more than 7,000 cryptocurrency wallets, with at least ¥1.7 billion in crypto transferred to wallets controlled by the group.
Japan’s National Police Agency (NPA) has detailed how the North Korea-linked cyber group WaterPlum, also known as Contagious Interview, targeted IT professionals through fake recruitment processes and malicious coding assignments.
According to an official press release published Friday, the NPA said WaterPlum targeted software developers and other technical workers in Japan, the United States, Europe and other regions. The investigation involved the U.S. Federal Bureau of Investigation (FBI), the U.S. Department of Defense Cyber Crime Center, Australian agencies and German authorities.
The NPA said WaterPlum infected more than 30,000 devices across more than 100 countries and regions between December 2025 and July 2026. Investigators identified information linked to more than 7,000 cryptocurrency wallets, while at least ¥1.7 billion in cryptocurrency was transferred to wallets controlled by the group.
Fake recruitment used to deliver Malware
According to the NPA, WaterPlum approached IT workers through social media, job websites, freelance platforms and other recruitment channels. Attackers allegedly posed as recruiters or representatives of companies working in areas including artificial intelligence, cryptocurrency and NFTs.
Applicants were then asked to participate in technical interviews or complete coding assignments. In some cases, they were instructed to download development files or execute code while troubleshooting software or completing programming tasks.
The NPA said malicious code was embedded in some of those files and projects.
Investigators linked the campaign to malware including BeaverTail, InvisibleFerret and OtterCookie, which could provide remote access and collect information from compromised devices.
Attackers sought wallet data and private keys
Once a device was compromised, attackers could access information stored on the computer.
The NPA said the stolen information included:
- Browser-stored credentials
- Clipboard data
- Keystrokes and screenshots
- Cryptocurrency wallet information
- Private keys and seed phrases
- Identity documents and other files
The NPA also reported that cryptocurrency was subsequently transferred to wallets controlled by WaterPlum.
The NPA’s findings show that the campaign involved not only credential theft but also attempts to obtain information that could provide access to digital assets.
North Korean IT workers used false identities
The investigation also uncovered a separate but related operation involving North Korean IT workers who obtained overseas employment under false identities. According to the NPA and FBI, some workers used intermediaries and remote-access infrastructure to perform programming and web-development jobs for companies in Japan and other countries.
Japanese investigators identified a “laptop farm” where computers located at a local intermediary’s residence were remotely operated by North Korean IT workers. The setup allowed workers to perform jobs while obscuring their actual locations. Investigators also identified the use of virtual private servers and other remote-access infrastructure.
The NPA said related investigations found that several hundred million yen had been transferred overseas through these IT-worker activities.
bitFlyer case shows recruitment warning signs
The NPA also disclosed a 2025 recruitment case involving Japanese cryptocurrency exchange bitFlyer.
An applicant seeking an engineering position allegedly used a resume that investigators later assessed as containing a false identity. The applicant claimed to be Malaysian and living in Finland while using multiple VPN services during the recruitment process.
According to the NPA, investigators noticed inconsistencies during the online interview, including differences between the applicant’s spoken English and the background listed on the resume. The applicant also reportedly gave vague answers to technical questions, repeatedly looked at another monitor, and had other voices audible in the background.
The applicant reportedly resisted relocating to Japan and requested payment in cryptocurrency. bitFlyer did not hire the applicant, and the NPA said the incident did not result in damage to the exchange.
Japanese reporting later identified overlapping IP addresses between the applicant, North Korean IT-worker activity, and WaterPlum-related infrastructure.
NPA links the activities to North Korea’s 313th Bureau
The NPA and FBI said their investigation identified infrastructure and other connections between WaterPlum’s cyber activity and operations involving North Korean IT workers.
The agencies assess that WaterPlum and some of the related IT-worker activity were operating under the direction of North Korea’s 313th Bureau of the Workers’ Party of Korea.
The two activities served different purposes. WaterPlum’s campaign focused on compromising devices and obtaining cryptocurrency and sensitive information, while the IT-worker operation involved obtaining overseas employment and generating foreign currency.
The agencies’ attribution is an investigative assessment rather than a court finding.
NPA warns companies about recruitment and code risks
The NPA said companies can face security risks even when they do not knowingly hire North Korean IT workers. Workers using false identities may gain access to source code, credentials, internal systems and other sensitive information.
The agency recommended verifying applicants’ identities, employment histories, technical qualifications and stated locations before granting access to company systems.
Companies were also advised to limit contractor access to the systems and information required for their work.
The NPA separately warned against running unfamiliar code on computers containing sensitive information or cryptocurrency assets. Where code needs to be tested, investigators recommended using isolated environments such as virtual machines.
For unfamiliar VS Code projects, the agency recommends using Restricted Mode and reviewing configuration files such as .vscode/tasks.json before allowing code to run.
The guidance is particularly relevant to technology and crypto companies whose developers or contractors may have access to private keys, source code, cloud infrastructure, and wallet-related systems.
Earlier North Korean campaigns also targeted crypto
The WaterPlum investigation comes alongside other cases involving North Korea-linked groups and cryptocurrency.
In September, Arkham data covered wallets linked to the Lazarus Group moving more than $30 million through Hyperliquid’s HyperUnit infrastructure. The funds were reportedly converted from Bitcoin into Ethereum and Solana before being routed across multiple networks and exchanges.
A separate July 2026 report covered activity attributed to BlueNoroff, another North Korea-linked group. Attackers reportedly used fake Zoom meeting invitations sent through trusted Telegram contacts to distribute malware.
These cases involve different groups and techniques but provide broader context for the methods North Korea-linked actors have used to target cryptocurrency and technology workers.
Also Read: Nostra Halts Starknet Money Market After $3.5M NSTR Oracle Exploit
