The U.S. Federal Bureau of Investigation and Japan’s National Police Agency have issued a joint warning about a North Korea-linked campaign targeting cryptocurrency wallets. The alert urges individual holders and crypto-sector organizations to treat unsolicited communications and unverified software as high-risk vectors for asset theft.
Japanese authorities identified the cluster as WaterPlum, also known as Contagious Interview. Between December 2025 and July 2026, the campaign infected more than 30,000 devices and stole wallet-related data from over 7,000 crypto wallets across more than 100 countries. Wallets controlled by the attackers received at least $10.71 million in cryptocurrency, roughly ¥1.7 billion.
The operation primarily targeted IT professionals, developers, blockchain workers, Web3 engineers, and Web designers through fake job offers on social media, job boards, freelance platforms, and gig-work sites. Attackers impersonated cryptocurrency, AI, and NFT companies and recruitment agencies. Victims were asked to complete coding tasks or technical interviews, which led to malware downloads from development platforms and code repositories. The malware families included BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle, capable of stealing passwords, screenshots, keystrokes, clipboard data, private keys, and seed phrases.
The investigation uncovered “laptop farms” operated by North Korean IT workers and local supporters, allowing operatives to hide their identities. The NPA also described a suspicious application to Japanese exchange bitFlyer in May 2025 using stolen identity information and VPN services. Authorities said matching IP addresses link WaterPlum and North Korean IT activity, and both are believed to be connected to Bureau 313, part of North Korea’s Workers’ Party Central Committee.
Law enforcement advised verifying software updates, using hardware wallets, enforcing least-privilege access for signing keys, and conducting high-risk work in virtual machines or isolated environments. Because Bitcoin transactions settle irreversibly, agencies stressed that wallet defenses must be in place before an attack rather than after funds are stolen.