North Korean hacker group known as WaterPlum was behind a cyberattack spanning more than 100 countries, including Japan, that resulted in the theft of cryptocurrency worth approximately US$10.71 million, according to Japan’s National Police Agency (NPA). The figure is the US dollar equivalent of ¥1.7 billion cited in the joint advisory issued by authorities from Japan, the United States, Australia and Germany.
WaterPlum infected at least 30,000 devices between December last year and July this year and obtained funds or account credentials from more than 7,000 cryptocurrency wallets, according to the warning document. The campaign targeted individual IT professionals, including web designers, engineers and specialists working in cryptocurrency, blockchain and Web3 technologies.
The findings were released under a framework known as “public attribution”, which is intended to deter cyberattacks by publicly identifying the groups or government agencies believed to be responsible. The joint document was signed by seven organisations from four countries, including the NPA and the U.S. Federal Bureau of Investigation.
According to the NPA, WaterPlum posed as corporate headhunters recruiting information technology professionals. The group sent malware-infected files disguised as technical assessments, exploiting the recruitment process to gain access to victims’ computers and steal cryptocurrency credentials. The joint advisory said at least US$10.71 million in cryptocurrency was transferred to the Democratic People’s Republic of Korea on behalf of the group.
The operation also formed part of a wider network involving North Korean IT workers living in North Korea, China and Russia. These workers obtained remote programming and other technology-related jobs under false identities, earning foreign currency while concealing their links to North Korea. The report said hundreds of millions of yen had been transferred to North Korea through such activities in recent years.
The network also relied on supporters in Japan who provided computers and servers used for the operations, as well as their own identification documents and financial accounts. Japanese authorities said they had identified, investigated and dismantled a “laptop farm” operated by an enabler in Japan. The authorities also obtained evidence that several hundred million yen in cryptocurrency had been transferred to foreign locations outside Japan.
Investigators found further links between the cyberattack and the foreign-currency operations through digital infrastructure. The report said IP addresses used by WaterPlum in the malware campaign matched those used in foreign-currency-earning activities and job applications.
The NPA and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is subordinate to the Central Committee of the Workers Party of Korea. The department is responsible for weapons development and IT strategy, according to the advisory.
The scale of the campaign illustrates how North Korean-linked operations have combined cybercrime, cryptocurrency theft and overseas IT employment to generate revenue. With more than 30,000 devices compromised across more than 100 countries, the WaterPlum investigation has prompted authorities to publicly expose the network and warn IT professionals and businesses about the risks associated with fraudulent recruitment and remote employment schemes.

