< Back to all clusters
[TECHNOLOGY] · Japan, United States, Australia, Germany · 4 sources

started · updated

WaterPlum: North Korean cyber group steals $10.7M in crypto via fake job interviews

Security agencies from Japan, the United States, Australia, and Germany have issued a joint advisory regarding a North Korean cyber group known as WaterPlum. The group, which is allegedly operating under the command of the Workers' Party of Korea's 313 General Bureau, has utilized sophisticated social engineering tactics to steal cryptocurrency.

WaterPlum targets software developers and IT professionals by posing as recruiters for AI, cryptocurrency, and NFT companies. Through fake job offers and technical interviews, the group tricks victims into downloading malware, which allows them to steal private keys and seed phrases. This campaign has reportedly infected over 30,000 devices across more than 100 countries and resulted in the theft of approximately 1.7 billion yen (roughly $10.7 million) from over 7,000 cryptocurrency wallets.

In Japan, authorities identified and dismantled a laptop farm used by North Korean IT workers to mask their locations and conduct fraudulent activities. Additionally, the National Police Agency revealed that a suspected North Korean IT worker attempted to apply for an engineering position at the cryptocurrency exchange bitFlyer in May 2025. The exchange avoided a breach after noticing suspicious behavior during the online interview process.

Entities

FBI · National Police Agency · North Korea · Waterplum · bitFlyer

Claims

What the coverage asserts, and how many sources carry each claim.