North Korea-Linked Hackers Infect 30,000 Devices, Steal Crypto Wallet Data
North Korean hackers have been linked to a massive cyberattack that infected over 30,000 devices and stole data from more than 7,000 crypto wallets worldwide. The attacks, which took place from December 2025 to July 2026, targeted victims in over 100 countries and were carried out by the North Korea-linked group WaterPlum.
WaterPlum used fake job offers on social media and online job sites to target developers and tech professionals. The attackers also impersonated cryptocurrency, AI, and NFT companies to seem legitimate. Once a victim accepted a fake offer, they would be asked to complete coding tasks or technical interviews with the group.
The malicious files were found on online development platforms and code repositories, which victims used in their assignments or software troubleshooting. WaterPlum utilized multiple malware families, including BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle, to infect devices. The malware could create access to infected computers, take passwords, screenshots, keyboard input, and clipboard data.
Authorities discovered that wallets controlled by WaterPlum received at least $10.71 million in cryptocurrency. The Japanese government called the facilities used by North Korean IT workers 'laptop farms,' where employees worked remotely using virtual private servers and crowdsourcing platforms. An investigation also uncovered a suspected North Korean IT worker who applied for a job at bitFlyer, a Japanese cryptocurrency exchange, using someone else's identity information.