
Japanese police, the FBI, and other partners issued a warning about the North Korean group WaterPlum, linked to hacking approximately 30,000 devices and compromising over 7,000 cryptocurrency wallets.
According to the investigation, the group transferred about 1.7 billion yen ($10.71 million) in stolen digital assets to North Korea.
Hackers from WaterPlum have been associated with the 313 Bureau of North Korea’s Department of Military Industry.
The group’s scheme involves “interviews” and “test tasks.” The perpetrators pose as employers and recruiters, including on behalf of companies in the AI and cryptocurrency sectors. They sent victims malicious files, allegedly to test skills or fix issues during interviews.

Criminals take control of devices using trojans and info-stealers. WaterPlum then steals browser data, private keys, seed phrases, and identity documents. The warning mentions malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
The document lists signs of suspicious job seekers:
- refusal of in-person meetings;
- requests for salary payments in cryptocurrency;
- video and audio glitches, foreign voices, and reading answers from another screen during interviews.
Authorities also revealed WaterPlum’s connection to a scheme involving North Korean IT workers who secure remote jobs through intermediaries and so-called “laptop farms.” These are platforms where computers, formally with contractors, are remotely controlled from other countries.

Japanese authorities stated they have identified and shut down such a farm operated by a local intermediary for the first time. According to the investigation, the group transferred several hundred million yen abroad in cryptocurrency.
Earlier, in August, analysts from Genians warned about North Korean hackers using AI for planning and executing attacks.
