Key facts
- North Korean actors stole around $10.71 million from over 7,000 crypto wallets.
- The group targeted web designers, engineers, and specialists in crypto, blockchain, and Web3.
- At least 30,000 devices across more than 100 countries were infected between December 2025 and July 2026.
- Malware families used include BeaverTail, InvisibleFerret, and StoatWaffle.
- Japanese authorities dismantled a "laptop farm" used to facilitate the remote operation.
- North Korea-linked groups were responsible for 60% of crypto theft losses in 2025, totaling $2.06 billion.
A sophisticated North Korean cybercrime operation, known as WaterPlum or Contagious Interview, has successfully defrauded cryptocurrency users of approximately $10.71 million by posing as legitimate recruiters. The group targeted individuals with skills in web design, engineering, and blockchain technology, luring them into downloading malware-disguised coding assignments under the guise of technical interviews. This tactic led to the compromise of over 7,000 cryptocurrency wallets and infected more than 30,000 devices across over 100 countries between December 2025 and July 2026.
Joint advisories from agencies including Japan's National Police Agency, the U.S. FBI and Department of Defense Cyber Crime Center, Australia's Cyber Security Centre, and Germany's BND and BfV detailed the operation. Investigators observed the actors using AI for voice and face manipulation during interviews, practicing Japanese pronunciation, and relying on free machine-translation tools. The group also celebrated North Korean holidays, suggesting a direct link to the country's IT workforce.
Evidence linking the operation to North Korea's 313 General Bureau of the Munitions Industry Department includes shared IP addresses used for accessing laptop farms, crowdsourcing services, and job applications. Japanese authorities successfully dismantled a domestic "laptop farm," a crucial component where remote IT workers in North Korea, China, or Russia operate compromised computers. This marks the first such dismantling in Japan. The advisory named several malware families used in the attacks, including BeaverTail, InvisibleFerret, and StoatWaffle, which often hid within blockchain-themed repositories.
