Japan Links North Korea-Backed Hackers to 7,000 Stolen Crypto Wallet Records

Daily Feed
Japan Links North Korea-Backed Hackers to 7,000 Stolen Crypto Wallet Records

Japan says a North Korea-linked hacking crew stole more than 7, 000 crypto wallet records, infected more than 30, 000 computers, and used fake job offers to trap developers in a recruitment scam with malware attached.

  • WaterPlum used fake hiring tests to target crypto and software workers.
  • More than 7, 000 wallet records were stolen, and controlled wallets received at least 1.7 billion yen.
  • Japan says the same infrastructure also supported North Korean IT worker operations and a domestic laptop farm.
  • A suspected North Korean applicant tried to get hired at bitFlyer using someone else’s identity.

Japan’s National Police Agency announced the findings on Sept. 18, alongside the National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, and agencies in Australia and Germany. The actor named in the disclosure is WaterPlum, which authorities tie to a campaign commonly known as Contagious Interview.

The setup is ugly, but not complicated. Targets were approached through fake companies in artificial intelligence, cryptocurrency, and NFT sectors. They were then sent files disguised as interview tasks, coding tests, or tools to diagnose video conferencing software. Open the wrong file, and the job hunt turns into an infection chain.

According to Japanese authorities, more than 30, 000 computers were likely infected across more than 100 countries and regions. The main targets included web designers, engineers, and people working in crypto, blockchain and Web3, exactly the sort of people who may keep sensitive credentials, source code, and wallet access within reach.

The wallet theft is especially nasty. Japanese authorities said more than 7, 000 cryptocurrency wallet records were stolen, and wallets controlled by WaterPlum received at least 1.7 billion yen, or roughly $10.7 million at the exchange rate cited by Japan. That figure refers to funds received by those wallets, not necessarily pure profit. Some of it may have moved through the network rather than stayed there, but the scale is still substantial.

The malware stack reads like a bad joke written by people who don’t have any. Authorities named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, and said the code was placed inside malicious NPM packages. NPM packages are reusable code libraries developers download for JavaScript projects. That matters because the whole trick is poisoning something developers already trust.

Once the malware landed, it reportedly pulled out browser credentials, keystrokes, screenshots, clipboard data, private keys, seed phrases, passports, and driver’s licenses. In crypto, that is a brutal menu. A seed phrase can restore a wallet. A private key can sign transactions directly. If attackers get either, the blockchain doesn’t care how sorry anyone feels afterward.

Japan and U.S. authorities assessed that WaterPlum and some North Korean IT workers operate under Bureau 313 of the Workers’ Party of Korea’s Munitions Industry Department. That is an attribution, not a public organizational chart carved in stone, but it points to something larger than one hacking crew freelancing for spare change.

In other words: this is not just about theft. It is also about foreign currency generation.

Japanese investigators said they dismantled what they described as the first known domestic “laptop farm” tied to North Korean IT workers in Japan. A laptop farm is a physical setup where computers are kept in one place and remotely controlled from elsewhere to hide the operator’s real location. In this case, a local facilitator kept the machines at their residence while workers used them remotely, and identity documents from people living in Japan were used in some cases to impersonate them.

That arrangement is a neat little fraud engine: fake identity, masked location, remote control, and a payment route that can be routed through facilitators. Very efficient. Very criminal. Very much the sort of thing that flourishes when employers treat identity checks like annoying admin instead of basic security.

Japanese authorities said some of the workers linked to the probe sent cryptocurrency and other assets worth hundreds of millions of yen overseas. The broader network operated from North Korea, China, Russia, and smaller bases in Africa and Southeast Asia, according to the findings. The geography matters less than the method: proxies, VPNs, remote control, and crypto payments make it easy to hide in plain sight until someone notices the paper trail is nonsense.

The bitFlyer case makes that concrete. In May 2025, a suspected North Korean IT worker applied for an engineering role using another person’s identity and a Gmail address. The applicant accessed the hiring system through NETNUT Proxy, Astrill VPN, and High Speed Rabbit Proxy, anonymity tools used to hide the real location, and claimed to be Malaysian while living in Finland. The applicant also resisted relocating to Japan and insisted on being paid in cryptocurrency.

bitFlyer spotted the suspicious behavior, did not hire the applicant, and reported no damage. That is the ideal outcome when someone shows up wearing a borrowed identity and a crypto-only paycheck demand.

Japanese authorities also pointed to a similar attempt detected at Kraken, which suggests this is not a one-off embarrassment for one exchange or one country. It is part of a wider pattern of infiltration attempts across the crypto hiring market.

The joint disclosure by Japan, the United States, Australia, and Germany shows how seriously officials are treating the overlap between cybercrime and fake employment. The FBI and the U.S. Department of Defense Cyber Crime Center were involved in the investigation, and Japan’s Foreign Ministry said the four countries jointly disclosed WaterPlum’s tactics and the North Korean IT worker activity.

That coordination is telling. One country sees a suspicious applicant. Another sees malware hitting a developer. Another sees funds moving through wallets. Put the pieces together and the picture is no longer “some bad actors on the internet.” It is a cross-border income machine.

Comparable U.S. cases show the pressure is building. According to the figures cited in the disclosure, two U.S. men received 18-month prison sentences in 2026, and the U.S. Department of Justice said those schemes involved nearly 70 companies and generated more than $1.2 million. Over a five-month period, the number of laptop-farm facilitators sentenced in the U.S. reached eight. A federal judge in September also ordered forfeiture of roughly $212, 700 in USDC and USDT, while the Justice Department’s broader effort involved more than $7.74 million in digital assets.

Those numbers should be read carefully. Some reflect proceeds, some reflect traced flows, and some reflect forfeiture actions rather than final recovered losses. But the direction is clear enough: authorities are trying to cut off both the hacking side and the fake-employment side of the same operation.

There is also a useful warning here for companies, especially in crypto and software. Remote hiring is now part of the attack surface. If a candidate’s claimed location does not make sense, if the contact details are shaky, if the person pushes hard for crypto payment, or if the “technical assessment” comes with a random file attachment from a stranger, that is not a quirky HR problem. That is a security problem with a paycheck attached.

Japanese authorities said they found matching IP infrastructure between the WaterPlum attacks, North Korean IT workers using laptop farms and crowdsourcing services, and the bitFlyer applicant. That overlap is the real story: the same operational plumbing appears to support malware, impersonation, and revenue generation. The old line between cybercrime and labor fraud is getting very thin.

Key questions and takeaways

  • What is WaterPlum?
    WaterPlum is the name Japanese authorities use for the North Korea-linked hacking group associated with the Contagious Interview campaign.
  • Why are crypto workers being targeted?
    Developers, engineers, and blockchain staff often handle credentials, wallet access, and sensitive code. That makes them high-value targets for theft and infiltration.
  • What is a laptop farm?
    It is a physical setup where computers are kept in one place and remotely controlled to disguise the user’s real location.
  • Why do seed phrases and private keys matter so much?
    Seed phrases can restore a wallet, and private keys can authorize transfers directly. If attackers steal them, funds can be moved fast.
  • Did bitFlyer hire the suspicious applicant?
    No. bitFlyer identified the suspicious behavior, did not hire the applicant, and reported no damage.
  • What is the biggest lesson for companies?
    Remote hiring needs real verification. Location, identity, qualifications, and payment demands all need scrutiny, especially when crypto is involved.

North Korea-linked operators are not just stealing crypto. They are running a layered business model built on malware, fake hiring, identity fraud, and cross-border cash-out routes. That kind of efficiency thrives when companies are sloppy and assume remote work automatically means trustworthy. It doesn’t.

Further reading

Useful context on the North Korea-linked hiring scam, the malware layer, and the broader fake-worker playbook:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog