North Korean Hackers Compromise 30,000 Devices Globally in Widespread Crypto Heist
A North Korean hacking group has been linked to the compromise of over 30,000 devices across more than 100 countries and regions between December 2025 and July 2026. Japan's National Police Agency (NPA) identified the group as WaterPlum, also known as Contagious Interview, which targeted software developers and IT professionals through social media and online job platforms.
The attackers impersonated legitimate AI, cryptocurrency, and NFT companies to present attractive recruitment opportunities to potential victims. Once a victim was compromised, malicious code would be downloaded onto their system, allowing the hackers to steal sensitive information, including browser credentials, screenshots, keystrokes, private keys, and cryptocurrency wallet data.
The malware, which included families such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, was designed to collect sensitive information from infected computers. The hackers stole more than 7,000 wallet-related records during the campaign, with at least $10.71 million in crypto assets transferred to wallets controlled by WaterPlum.
The NPA warned that targeted companies could face theft of sensitive information, intellectual property, and additional network compromise. Japan also identified its first domestic 'laptop farm' linked to North Korean IT workers, which allows workers operating remotely to control computers located at supporters' homes.