North Korean Hackers Targeted IT Professionals with Fake Job Listings and Stole Data from 7,000 Crypto Wallets
- North Korean hackers used fake job postings to steal cryptocurrency.
- They infected 30,000 devices and stole data from 7,000 crypto wallets.
- Specialists from more than 100 countries were among the victims.
Japan’s National Police Agency (NPA), together with the U.S. FBI, as well as Australian and German law enforcement agencies, uncovered the activities of the North Korea-linked cyber group WaterPlum. According to the agencies, from December 2025 to July 2026, the group infected more than 30,000 devices across more than 100 countries and regions with malware and stole data from more than 7,000 cryptocurrency wallets.
Crypto assets worth at least 1.7 billion Japanese yen, or about $10.8 million, were transferred to wallets controlled by WaterPlum.
WaterPlum Disguised Attacks as Job Postings
The group’s primary targets were IT professionals, including web developers, engineers, and specialists in cryptocurrency, blockchain, and Web3. WaterPlum posed as legitimate AI, crypto, and NFT companies or recruiting services and offered candidates attractive job openings.
During interviews or while completing test assignments, victims were asked to download malicious programs from collaboration platforms or code repositories. To distribute malware, the group used, among other things, NPM packages into which it embedded the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle families.
After infection, the attackers installed a backdoor, maintained remote access, and stole sensitive data. The targeted information included:
- Browser credentials
- Keystroke logs, clipboard contents, and screenshots
- Cryptocurrency wallet data, including private keys and seed phrases
- Documents and images of identity documents
According to the NPA and the FBI, WaterPlum and some North Korean IT workers operate under the direction of the 313th General Bureau of the Munitions Industry Department of the Central Committee of the Workers’ Party of Korea.
North Korean IT Workers Used “Laptop Farms”
Law enforcement also, for the first time in Japan, uncovered and dismantled a so-called laptop farm — computers set up in the home of a local intermediary and remotely controlled by North Korean IT workers. According to the NPA, cryptoassets and other funds worth several hundred million yen were transferred abroad through such schemes.
In May 2025, one of the suspects linked to the North Korean IT network also applied for an engineering role at the Japanese crypto exchange bitFlyer. The candidate used a VPN, submitted a resume under another person’s name, and insisted on the option to work remotely and be paid in cryptocurrency. The company spotted suspicious signs during the interview and did not hire him.
Law enforcement notes that the activities of North Korean IT workers may not be limited to earning foreign currency. They may also use access to corporate systems to steal confidential information, source code, and other data.
The NPA recommends that companies minimize contractors’ access to internal systems, verify candidates’ identities and qualifications, and use sandboxes or a restricted mode when working with unverified code. If a device is infected, the agency advises immediately isolating it from the network, and for cryptoassets — creating a new wallet from another device and transferring the funds there.
As a reminder, it recently became known that DPRK-linked groups infiltrated 1,640 companies in 57 countries and hunted for crypto keys.
Сообщение North Korean Hackers Targeted IT Professionals with Fake Job Listings and Stole Data from 7,000 Crypto Wallets появились сначала на INCRYPTED.
Source: Incrypted
