North Korean actors drained $11M from 7,000 crypto wallets via fraudulent job interview scheme, connected to WaterPlum hacking crew.
Security & Exploits ·
North Korean actors operating under the name WaterPlum have targeted more than 7,000 cryptocurrency wallets through a coordinated fraud scheme, extracting approximately $10.71 million and redirecting it to Pyongyang, according to a joint advisory from seven agencies across Japan, the U.S., Australia and Germany. The criminal group impersonates recruiters for technology and blockchain companies, approaching job candidates via social media, employment platforms and freelance marketplaces. During interviews, targets are induced to download malicious files—packaged as coding assignments or solutions to purported technical glitches—which install malware including BeaverTail, InvisibleFerret and StoatWaffle across at least 30,000 devices spanning over 100 countries between December 2025 and July 2026.
Intelligence assessments conclude that WaterPlum and North Korea's legitimate remote IT worker operations are managed by the same entity: the 313 General Bureau of the Munitions Industry Department. The connection rests on shared infrastructure, including identical IP addresses used to access laptop farms, engage crowdsourcing services and submit job applications. Operators employed AI face-swapping during video calls, practiced foreign language pronunciation via text-to-speech, and relied on free translation and AI services. Japanese authorities dismantled a domestic laptop farm—a first for that country—operated by a local enabler, uncovering evidence that hundreds of millions of yen in cryptocurrency had been moved outside Japan.
The advisory documents the infrastructure and tradecraft but does not disclose how many wallet holders remain unaware of compromise or whether recovery efforts are underway.