Principali approfondimenti:
- In today’s crypto scam news, North Korea-linked WaterPlum infected more than 30,000 devices.
- The campaign stole data from more than 7,000 crypto wallets.
- Controlled wallets received at least $10.71 million in crypto.
North Korea-linked hackers infected more than 30,000 devices across over 100 countries and regions between December 2025 and July 2026 in the latest scam news. Japan’s National Police Agency said WaterPlum stole information linked to more than 7,000 crypto wallets.
Authorities also found about $10.71 million transferred to wallets controlled by the group. The campaign combined crypto hacks with fake recruitment activity targeting technology workers.
Le investigation involved Japan’s National Police Agency, National Cyber Office, FBI, DC3, ASD, ACSC, BND and BfV. Authorities also examined North Korean IT workers involved in overseas employment and foreign-currency earning activity.

Crypto Hacks Use Fake Recruitment Campaigns
WaterPlum approached software developers, engineers and Web3 workers through social media, recruitment websites and freelance platforms. The hackers impersonated legitimate AI, crypto, NFT and recruitment companies while offering employment opportunities.
During those tasks, WaterPlum instructed candidates to download programs from collaborative development platforms and code repositories. The hackers sometimes presented the files as tools for fixing video-conferencing problems.
Meanwhile, WaterPlum distributed malicious NPM packages containing BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. These malware families supported remote access, credential theft, and data extraction.
The stolen information included browser credentials, clipboard contents, screenshots, keystrokes, private keys and wallet seed phrases. Attackers also targeted driver’s licenses, passports and other identity documents.
Crypto Scam Connect With Laptop Farms
Meanwhile, Japanese authorities identified the country’s first known domestic laptop farm connected to North Korean IT workers. Police dismantled computers located inside an enabler’s residence.
The workers remotely accessed those devices while seeking outsourced technology jobs. They also used virtual private servers to conceal their actual locations.
Additionally, some workers used identity documents belonging to other people when obtaining contracts. Others directed payments through bank accounts controlled by their enablers.
Authorities found that North Korean IT workers transferred crypto assets and other funds worth several hundred million yen overseas. Workers operated from North Korea, China, and Russia, among other locations.
Some WaterPlum members also completed web design and development work for companies in Japan and the United States. Investigators connected some activity to Bureau 313.
Notably, some members used Magicam face-swapping software during online interviews. They also used NaturalReader to practice Japanese pronunciation and free generative AI tools.
Hackers Target Japanese Crypto Exchange Jobs
The investigation also detailed a May 2025 engineering application submitted to Japanese crypto exchange bitFlyer. Authorities suspected the applicant was a North Korean IT worker.
The applicant used another person’s identity and submitted the application directly through bitFlyer’s recruitment system. The person also used Gmail and several VPN services.
Meanwhile, the résumé listed numerous programming, blockchain, truffa crypto, and cloud computing skills. It also claimed education in Europe and work experience across several countries.
However, bitFlyer identified inconsistencies during the online interview. The applicant said they were a Malaysian national and residing in Finland.
The applicant also resisted relocating to Japan and asked for salary payments in crypto. Interviewers observed repeated glances at another screen and background voices.
Video interruptions also occurred during the interview. BitFlyer did not hire the applicant, and the company reported no resulting damage.
The National Police Agency and FBI assessed that Bureau 313 plays a central role in both sets of activity. Bureau 313 operates under the Workers’ Party of Korea’s Munitions Industry Department.
NTT Security Japan and bitFlyer assisted authorities with the advisory. Japanese police also relied on private-sector information during their investigation.
L'articolo Crypto Scam: North Korean Hackers Target 7,000 Wallets è apparso per primo su The Coin Republic.





