WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets

Summary

North Korean-linked hackers, identified as WaterPlum, have compromised over 30,000 devices worldwide and stolen data from more than 7,000 cryptocurrency wallets between December 2025 and July 2026, according to reports from Japan’s National Police Agency and the FBI. The malware campaign has reportedly directed at least $10.71 million in crypto assets to wallets under their control. This infiltrating effort aligns with a broader trend of increased recruitment risks faced by cryptocurrency firms, which have seen operatives posing as job candidates to gain access to systems. Additionally, Japanese police announced the dismantling of a domestic laptop farm supporting North Korean IT workers, emphasizing the ongoing international collaboration to combat state-linked cybersecurity threats.

Analysis

FBI: The FBI is the primary federal law enforcement agency in the United States, with a major focus on cybercrime and national security threats including state-sponsored hacking. It partnered with Japan's National Police Agency to attribute and publicize the WaterPlum campaign linked to North Korea. The bureau has been active in tracking cryptocurrency thefts by such groups. bitFlyer: bitFlyer is a major Japanese cryptocurrency exchange offering trading and related financial services. A suspected North Korean IT worker applied for an engineering position there in May 2025, highlighting recruitment risks in the sector. The exchange operates in a jurisdiction actively monitoring North Korean cyber activities. WaterPlum: WaterPlum is a North Korea-linked hacking group known for deploying malware through social engineering tactics aimed at crypto, AI, and NFT job seekers. In this incident, it infected tens of thousands of devices to harvest data from cryptocurrency wallets across multiple countries. The group has been tied to efforts supporting North Korean IT operations abroad. Japan's National Police Agency: Japan's National Police Agency is the central coordinating body for law enforcement across the country, overseeing criminal investigations and international cooperation on cyber threats. It collaborated with the FBI to expose the WaterPlum malware operation targeting crypto users worldwide. The agency also took action against domestic infrastructure supporting North Korean IT activities. Recruitment Risks: Crypto firms continue to face infiltration attempts by operatives posing as job candidates in technical roles. Cybersecurity Collaboration: International law enforcement agencies have increased joint operations to counter state-linked malware campaigns targeting digital assets.

Categories

crypto
View Original Tweet