A North Korea-linked hacking group used fake job offers to target IT workers and steal cryptocurrency, Japan’s NPA said Friday.
The group, known as WaterPlum, infected more than 30,000 devices across over 100 countries from December 2025 through July 2026. Investigators also found information linked to more than 7,000 crypto wallets.
At least ¥1.7 billion in cryptocurrency later moved to wallets controlled by the group, according to the NPA.
Fake Jobs Target IT Workers
WaterPlum posed as recruiters for companies working in AI, crypto and NFTs. Attackers contacted developers through social media, job websites and freelance platforms before sending technical interviews or coding assignments.
Some applicants received development files or projects and were asked to run code while completing the tasks. The NPA said attackers embedded malicious code in some files, allowing malware to access information stored on victims’ computers.
The malware could collect browser credentials, keystrokes, screenshots and clipboard data. It also targeted crypto wallet information, private keys, seed phrases and identity documents.
NPA Warns of North Korean Links
The NPA, FBI and other agencies linked WaterPlum’s activity to North Korean operations. They also identified “laptop farms” where North Korean IT workers remotely operated computers at intermediaries’ locations.
The NPA urged companies to verify workers’ identities, employment histories and locations. It also advised developers to test unfamiliar code in isolated environments.
Related: Crypto Tracing Helps UAE and Sweden Bust $7 Million Laundering Ring
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.