Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets
A North Korea-backed hacking group contaminated greater than 30,000 computer systems in over 100 international locations. It additionally stole knowledge from greater than 7,000 crypto wallets, Japan’s National Police Agency and the FBI mentioned Friday.
Wallets the group controls acquired at the least $10.71 million in digital property between December 2025 and July 2026. The companies name the group WaterPlum, additionally tracked as Contagious Interview.
How Fake Recruiters Reached 7,000 Crypto Wallets
WaterPlum poses as a headhunter for synthetic intelligence, cryptocurrency and non-fungible token corporations. It approaches builders on social media, job boards and freelance marketplaces.
“WaterPlum actors pose as potential employers to focus on software program builders and IT professionals worldwide underneath the pretext of enticing job alternatives,” Japan’s National Police Agency and the FBI said within the joint advisory.
Applicants are then requested to sit down a technical interview or end a coding take a look at. The group tells them to obtain recordsdata from code-sharing websites. The pretext is a damaged video name or the project itself.
Those recordsdata carry malware. The applications hunt for browser passwords, screenshots and keystrokes. They additionally take the key keys that management a crypto pockets, the software program folks use to carry digital cash.
BeInCrypto reported in August on a researcher who spent 22 months contained in the group’s servers. He mapped 1,640 victims in 57 international locations. Friday’s official tally is roughly 18 occasions bigger.
Japan Dismantles Its First Laptop Farm
Police additionally shut down the nation’s first recognized laptop computer farm. Local helpers stored the computer systems of their properties. North Korean employees overseas managed them remotely and posed as Japanese residents to win freelance contracts.
Those employees despatched a number of hundred million yen value of crypto abroad, investigators mentioned. The identical web addresses linked the farm to the hackers.
“The NPA and the FBI assess each WaterPlum cyber actors and a few North Korean IT employees function underneath the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.”
One suspected North Korean utilized for an engineering function at Japanese alternate bitFlyer in May 2025 utilizing a stolen resume. Interviewers observed he refused to relocate and demanded cost in crypto. He appeared to learn solutions off a second display screen, and he was not employed.
Earlier campaigns leaned on deepfake recruitment video calls to achieve senior workers. Investigators now inform engineers to run recruiter code inside a sandbox, a sealed take a look at space walled off from actual recordsdata.
The submit Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets appeared first on BeInCrypto.
