Key Highlights
- A seven-nation intelligence coalition publicly attributed a global cryptocurrency theft campaign to the North Korean group WaterPlum (alias “Contagious Interview”), linking the operation to the 313 General Bureau of the Munitions Industry Department under the Central Committee of the Workers’ Party of Korea.
- Fake job recruitment schemes targeting software developers compromised over 30,000 devices across 100+ countries and breached approximately 7,000 cryptocurrency accounts, diverting an estimated 1.7 billion yen ($10.71 million) to North Korea between December 2025 and July 2026.
- Japanese authorities dismantled a domestic “laptop farm” used to conceal the physical location of North Korean IT workers, marking the first such intervention in Japan and exposing a broader labor fraud network routing hundreds of millions of yen annually to Pyongyang.
Seven-Agency Coalition Unmasks WaterPlum Operation
In a coordinated announcement on Friday, September 18, 2026, seven national security agencies jointly exposed a North Korean cyber operation that has been masquerading as technology recruiters to steal cryptocurrency from information technology professionals worldwide. The advisory bears the seals of Japan’s National Police Agency (NPA) and National Cybersecurity Office, the United States Federal Bureau of Investigation (FBI) and Department of Defense Cyber Crime Center (DC3), Australia’s ASD Cyber Security Centre, and Germany’s Bundesnachrichtendienst (BND) and Bundesamt für Verfassungsschutz (BfV).
The disclosure was made under a “public attribution” framework—a deliberate diplomatic and legal strategy designed to deter future attacks by formally naming the state sponsor and operational units behind malicious cyber activity. According to the joint assessment of the NPA and FBI, the hackers operating under the WaterPlum banner, alongside a contingent of North Korean IT workers, operate under the direct command of the 313 General Bureau of the Munitions Industry Department, a subunit of the Central Committee of the Workers’ Party of Korea. This chain of command confirms the operation as a state-directed revenue generation program for Pyongyang’s weapons development, a charge U.S. intelligence agencies have leveled repeatedly in previous North Korean cryptocurrency theft campaigns—allegations the North Korean regime has consistently denied.
Fake Recruitment Lure: How the Malware Campaign Worked
The threat actors posed as hiring managers at artificial intelligence firms, cryptocurrency ventures, and non-fungible token startups, extending attractive job offers to software developers. Candidates were guided through technical interviews or coding assignments, then instructed to download and execute files framed as assessment tasks. Those files were weaponized: they carried malware embedded in Node Package Manager (npm) packages, deploying a suite of custom payloads identified as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Once installed, the malware established persistent backdoors via remote-access trojans, enabling operators to harvest browser-stored passwords, keystroke logs, screenshots, and—critically—the private keys and seed phrases that control cryptocurrency wallets. Between December 2025 and July 2026, the campaign infected more than 30,000 devices in over 100 countries and compromised sensitive credentials for roughly 7,000 cryptocurrency accounts, yielding the 1.7 billion yen ($10.71 million) in diverted assets.
Malware Arsenal and Technical Infrastructure
The five identified malware families represent a modular toolkit designed for credential theft, system surveillance, and long-term access maintenance. Researchers note the use of legitimate software supply chains—specifically the npm registry—as a delivery vector, allowing the malicious packages to blend with routine development workflows. The stolen private keys and seed phrases provided direct, irreversible control over victims’ on-chain assets, facilitating rapid liquidation and laundering through North Korea’s established cryptocurrency mixing and exchange networks.
Japan’s First Laptop Farm Takedown
The advisory reveals a second, parallel operation: North Korean IT workers residing in North Korea, China, and Russia fraudulently secured remote programming and web-development contracts, funneling hundreds of millions of yen in wages back to the regime over several years. To obscure the true geographic origin of this labor, the network enlisted local facilitators to operate “laptop farms”—physical locations housing devices that made the remote workers appear to be logging in from within the hiring country.
Japanese investigators identified, raided, and shut down one such laptop farm operated by a domestic enabler, marking the first known disruption of this infrastructure type in Japan. The takedown illustrates how North Korea’s revenue generation blends cyber intrusion with labor fraud, exploiting the global shift toward remote work to bypass sanctions and financial controls.
Why This Matters
The WaterPlum attribution arrives amid a sharp escalation in state-sponsored cryptocurrency theft. The advisory cites a 420% surge in malware targeting public blockchains, with North Korea and Iran identified as primary originators. In June 2026, G7 leaders formally classified North Korean cryptocurrency theft as a significant security threat, citing an estimated $6.75 billion stolen since 2016 by Pyongyang-linked actors. Independent research presented at Black Hat by Vangelis Stykas corroborates the scale: his analysis traced North Korean infiltration into 1,640 companies across 57 countries, frequently initiated through the same fake job offers that deliver malware, as reported by Cryptopolitan. The seven-agency public attribution signals a strategic shift toward collective deterrence, exposing not only the hackers but the institutional command structure that directs them.
Frequently Asked Questions
What is WaterPlum and who controls it?
WaterPlum (also known by the alias “Contagious Interview”) is a North Korean cyber operation attributed by seven national intelligence agencies to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers’ Party of Korea. The group conducts cryptocurrency theft and labor fraud to fund North Korea’s weapons programs.
How did the fake job scheme steal cryptocurrency?
Attackers posed as recruiters at AI, crypto, and NFT companies. After interviews, victims were sent malware-laced npm packages (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) disguised as coding tests. The malware installed remote-access trojans, stealing browser passwords, keystrokes, screenshots, and—most critically—private keys and seed phrases for cryptocurrency wallets, enabling direct asset theft.
What is a “laptop farm” and why is Japan’s takedown significant?
A “laptop farm” is a physical facility where local enablers host devices that make North Korean remote workers appear to be logging in from within the hiring country (e.g., Japan). Japan’s disruption of such a farm is the first known case of its kind in the country, exposing a key infrastructure layer that allows North Korea to evade sanctions and labor laws while routing wages back to the regime.

