Hackers linked to North Korea posed as recruiters for AI, crypto and NFT firms to infect more than 30,000 computers in over 100 countries, according to a joint advisory from Japan’s National Police Agency and the FBI on Friday.
Wallets controlled by the group, tracked as WaterPlum or Contagious Interview, received at least $10.71 million in digital assets between December 2025 and July 2026, and data from more than 7,000 crypto wallets was compromised.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” — Japan’s National Police Agency and the FBI, in a joint advisory.
Applicants were then asked to participate in technical interviews or complete coding assignments. In some cases, the attackers reportedly presented the need to download files as part of a coding test or claimed the files were required to resolve problems with a video call.
The downloaded files contained malware capable of searching infected computers for browser passwords, screenshots and keystrokes. The malware also sought the private information and secret keys used to control crypto wallets, potentially allowing attackers to gain access to victims’ digital assets.
The scale of the campaign was significant. Investigators said the group infected more than 30,000 computers in over 100 countries, while data from more than 7,000 crypto wallets was compromised.
Crypto wallets received millions in stolen digital assets
The investigation found that crypto wallets controlled by the group received at least $10.71 million worth of digital assets between December 2025 and July 2026.
The findings highlight how recruitment scams can extend beyond the theft of personal information or corporate credentials. By targeting developers with technical assignments and employment opportunities, the attackers created a pathway to introduce malicious software onto victims’ devices and ultimately pursue access to crypto wallets.
BeInCrypto previously reported in August on a researcher who spent 22 months inside servers connected to the group. That investigation identified 1,640 victims across 57 countries. The latest figures from Japanese and US authorities are considerably larger, indicating a broader campaign than earlier research had documented.
The investigation also links the cyber operation to a wider network of North Korean IT activity.
“The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.” — Japan’s National Police Agency and the FBI, in a joint advisory.
Authorities said the connection suggests that the hacking operation and certain North Korean IT workers may be part of related activities associated with the country’s military-industrial structure.
Japan dismantles suspected North Korean laptop farm
Japanese authorities also shut down what investigators described as the country’s first known laptop farm linked to the wider operation.
Local helpers reportedly kept computers in their homes while North Korean workers based overseas remotely operated the devices. The workers allegedly used the computers to pose as Japanese residents and secure freelance contracts.
Investigators said those workers transferred several hundred million yen worth of cryptocurrency overseas. Internet addresses associated with the laptop operation were also linked to the hackers.
The investigation uncovered an example involving Japanese cryptocurrency exchange bitFlyer. In May 2025, a suspected North Korean national reportedly applied for an engineering position at the company using a stolen résumé.
Interviewers became suspicious after the applicant refused to relocate, requested payment in cryptocurrency and appeared to read answers from another screen. The individual was not hired.
The episode illustrates how the same broader ecosystem can combine employment fraud, remote access and cyber theft, with cryptocurrency providing a mechanism for transferring funds across borders.
Crypto wallets remain exposed to recruitment-based attacks
Investigators said earlier campaigns associated with the group relied on deepfake recruitment video calls to target senior employees. More recent activity has reportedly focused on convincing technical workers to download malicious code under the appearance of legitimate recruitment assignments.
The shift has increased the importance of security precautions for developers and other technology professionals who regularly download code from unfamiliar sources.
Investigators now recommend that engineers run recruiter-provided code inside a sandbox, an isolated environment designed to prevent potentially malicious programs from accessing real files and systems.
For crypto users, the campaign also demonstrates the risks surrounding crypto wallets when private keys or other sensitive credentials are exposed through compromised devices.
The investigation shows that the threat extends beyond cryptocurrency holders directly. Developers searching for jobs, companies recruiting technical workers and freelancers accepting coding assignments can all become potential entry points for malware designed to reach crypto wallets and other sensitive information.
With more than 30,000 computers reportedly infected and at least $10.71 million in digital assets received by wallets controlled by the group, authorities’ findings underscore the financial consequences of recruitment-themed cyberattacks.