Original source: npa.go.jp
Japan NPA and FBI Expose North Korean Hacker Group Using Fake Job Offers to Steal Crypto Assets
Compiled by Odaily Planet Daily (@OdailyChina); Translator | Asher (@Asher_0210)
KuCoin
Publisher
Sep 20, 2026 at 6:48 AM UTC · 7 min de lecture

Compiled by Odaily Planet Daily (@OdailyChina); Translator | Asher (@Asher_0210)
On September 18, multiple agencies including Japan's National Police Agency and the U.S. Federal Bureau of Investigation jointly disclosed that the North Korean hacking group WaterPlum (also known as "Contagious Interview") has long impersonated recruiters or cryptocurrency companies to lure developers into running malicious code under the guise of programming tests and project collaboration.
From December 2025 to July 2026, the organization infected over 30,000 devices in more than 100 countries, transferring funds or stealing account credentials from over 7,000 cryptocurrency wallets, involving at least $10.71 million in crypto assets.
Unlike past attacks that primarily targeted exchanges and large institutions, WaterPlum has further expanded its focus to individual developers, freelancers, and Web3 professionals. Attackers not only directly steal wallet assets but also use compromised computers and identity information to infiltrate the victims’ companies, paving the way for subsequent theft of trade secrets, extortion, or even impersonation of the victims in job applications.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
