In brief
- Police and intelligence agencies in Japan, the U.S., Australia and Germany said the group infected at least 30,000 devices across more than 100 countries.
- It took funds or credentials from over 7,000 crypto wallets and moved ¥1.7 billion, around $10.71 million, to North Korea.
- Japanese authorities dismantled a domestic "laptop farm" for the first time.
A North Korean crew that poses as recruiters to compromise developers has taken funds or credentials from more than 7,000 cryptocurrency wallets and moved around $10.71 million to Pyongyang, seven agencies across four countries said in a joint advisory published on September 18.
The group, which Japan's National Police Agency calls WaterPlum and the security industry knows as Contagious Interview, infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026. Targets were web designers, engineers and specialists in crypto, blockchain and Web3 work.
It is signed by Japan's National Police Agency and National Cybersecurity Office, the FBI and the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND foreign intelligence service and BfV domestic security agency.
The NPA and the FBI assess that both WaterPlum and some of North Korea's remote IT workers report to the 313 General Bureau of the Munitions Industry Department, which sits under the Workers' Party central committee. The two operations also used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs, which the agencies treat as evidence the two are one operation.

North Korea's hacking campaign
Actors impersonate AI, crypto or NFT companies, approach developers through social media, job boards and freelance marketplaces, then set a technical interview or coding task. Candidates are told to download files from developer platforms, either to finish the assignment or to fix an apparent fault in the video call. The advisory names five malware families carried in those packages, among them BeaverTail, InvisibleFerret and StoatWaffle, the last of which hides in blockchain-themed repositories.
The advisory also logs what investigators observed of the crew itself. Members used AI face-swapping software in interviews before cutting video and asking the candidate to do the same, blaming the connection. They practised Japanese pronunciation with text-to-speech tools, worked consistently on free machine-translation and AI tiers, and on holidays celebrated in North Korea played games and watched soccer videos instead of running their usual operations.
Japanese authorities also identified and dismantled a laptop farm run by a domestic enabler, the first such case in the country, finding evidence that several hundred million yen in crypto had moved abroad. A laptop farm is usually an enabler's home, where work computers are run remotely by IT workers in North Korea, China or Russia.
A Japanese crypto exchange turned away an applicant in May 2025 whose résumé claimed implausibly broad skills and whose English did not match the record. Other tells include refusing to meet in person, asking to be paid in crypto, and glancing repeatedly at a second screen.
The theft sits inside a far larger campaign. CertiK attributed 60% of all crypto theft losses in 2025, some $2.06 billion, to North Korea-linked groups, and April's $285 million Drift Protocol hack followed six months of attackers posing as a quantitative trading firm.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.