Crypto World

Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets

Published

on

A North Korea-backed hacking group infected more than 30,000 computers in over 100 countries. It also stole data from more than 7,000 crypto wallets, Japan’s National Police Agency and the FBI said Friday.

Wallets the group controls received at least $10.71 million in digital assets between December 2025 and July 2026. The agencies call the group WaterPlum, also tracked as Contagious Interview.

How Fake Recruiters Reached 7,000 Crypto Wallets

WaterPlum poses as a headhunter for artificial intelligence, cryptocurrency and non-fungible token firms. It approaches developers on social media, job boards and freelance marketplaces.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” Japan’s National Police Agency and the FBI said in the joint advisory.

Applicants are then asked to sit a technical interview or finish a coding test. The group tells them to download files from code-sharing sites. The pretext is a broken video call or the assignment itself.

Advertisement

Those files carry malware. The programs hunt for browser passwords, screenshots and keystrokes. They also take the secret keys that control a crypto wallet, the software people use to hold digital money.

BeInCrypto reported in August on a researcher who spent 22 months inside the group’s servers. He mapped 1,640 victims in 57 countries. Friday’s official tally is roughly 18 times larger.

Japan Dismantles Its First Laptop Farm

Police also shut down the country’s first known laptop farm. Local helpers kept the computers in their homes. North Korean workers abroad controlled them remotely and posed as Japanese residents to win freelance contracts.

Advertisement

Those workers sent several hundred million yen worth of crypto overseas, investigators said. The same internet addresses linked the farm to the hackers.

“The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.”

One suspected North Korean applied for an engineering role at Japanese exchange bitFlyer in May 2025 using a stolen resume. Interviewers noticed he refused to relocate and demanded payment in crypto. He appeared to read answers off a second screen, and he was not hired.

Earlier campaigns leaned on deepfake recruitment video calls to reach senior staff. Investigators now tell engineers to run recruiter code inside a sandbox, a sealed test area walled off from real files.

The post Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets appeared first on BeInCrypto.

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version