Japan, FBI Tie WaterPlum Campaign to Crypto Wallet Theft

Japan, FBI Tie WaterPlum Campaign to Crypto Wallet Theft

By: WEEX|2026/09/18 13:05:02

WEEX View

  1. The immediate market focus is whether law enforcement publishes wallet addresses, malware indicators, or exchange-facing alerts that can help platforms block related flows and identify compromised users.
  2. Exchanges and wallet providers may also need to watch for credential theft and device compromise among employees, contractors, and high-value users, especially where hiring workflows, code tests, or remote interview tools create entry points.
  3. The report’s reference to a dismantled “laptop farm” points to a broader operational risk: social-engineering campaigns tied to remote IT worker networks can reach both corporate systems and end-user wallets before any on-chain movement becomes visible.

A joint report issued by Japan’s National Cyber Coordination Center, the FBI, the U.S. Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, and Germany’s Federal Intelligence Service said the North Korean hacker group WaterPlum used fake recruitment approaches to infect more than 30,000 devices and steal information from over 7,000 cryptocurrency wallets.

According to the report, WaterPlum primarily targeted IT personnel and carried out attacks disguised as recruitment efforts. Authorities said the campaign sought to steal both confidential information and cryptocurrency assets. The activity covered the period from December 2025 to July 2026 and affected terminals in more than 100 countries and regions, including Japan.

The agencies said the campaign infected more than 30,000 terminals and stole information from more than 7,000 cryptocurrency wallets. They also said at least about 1.7 billion yen, or roughly $10.71 million, in crypto assets was transferred to wallets controlled by the attackers.

Japanese police said they seized and dismantled a “laptop farm” run by local supporters for North Korean IT workers to operate remotely. The Japanese police agency and the FBI assessed that WaterPlum and some North Korean IT workers were directed by the 313 Bureau of the Ministry of National Defense Industry of the Workers’ Party of Korea.

The report also said the group had previously posed as applicants for engineering roles at Japanese crypto exchange bitFlyer. Authorities said no actual employment took place in that case and bitFlyer did not incur losses. That separates the attempted infiltration from the confirmed wallet-related theft and device infections described in the broader campaign.

Fake recruitment and interview lures have become a recurring attack path in crypto-focused cybercrime. Recent security reporting has linked North Korea-related groups to campaigns targeting Web3 developers and crypto industry workers with malicious code, skills tests, and spoofed meeting links designed to compromise devices and harvest credentials or wallet access.

Why It Matters

This case brings together several risks that matter to the crypto industry at once: endpoint compromise, insider-style access attempts, and wallet theft tied to social engineering rather than a direct protocol exploit. That widens the threat model for exchanges, market makers, developers, and wallet users beyond smart-contract security alone.

It also reinforces how cross-border enforcement is increasingly central to crypto crime response when state-linked groups are involved. A coordinated assessment by police, intelligence, and cyber agencies can shape later compliance actions, wallet monitoring, and exchange controls even before a full public accounting of the laundering path emerges.

Milestones

2026/04/24
2026/05/09
2026/07/26
Security reporting said the North Korea-backed group HexagonalRodent used fake Web3 job offers and skills tests to induce developers to run malicious code.
Researchers said Lazarus ran an “infectious interviews” campaign that lured crypto and DeFi developers into cloning repositories containing malicious code.
BlueNoroff was reported to have used fake Zoom and Microsoft Teams meeting links to scan crypto wallets and push victims toward malware downloads.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

About WEEX View

WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.

-- Price

--
--
--
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com