The FBI and partner agencies said on Sept. 18 that North Korean WaterPlum actors infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from more than 7,000 cryptocurrency wallets. The joint advisory put the alleged value of cryptocurrency assets transferred to North Korea at 1.7 billion Japanese yen, or $10.71 million.
Wallet theft and global infections
An FBI-led cybersecurity alert identified WaterPlum as a North Korean cyber actor group. Authorities said the activity reached devices globally, rather than being confined to one market or region.
WaterPlum transferred 1.7 billion Japanese yen in cryptocurrency assets to North Korea, according to the accompanying Internet Crime Complaint Center advisory.
The notice did not specify which cryptocurrency assets comprised that amount or provide a breakdown of the compromised wallets.
Fake recruitment lures
WaterPlum allegedly used fake job offers and coding tests to target software developers and other IT professionals. Victims were sent malicious files carrying malware including BeaverTail, InvisibleFerret and OtterCookie, according to BleepingComputer.
The recruitment framing is central to the campaign’s reach: it put malicious code in the course of a purported hiring process aimed at technical workers. The FBI advisory’s count covers devices infected through the activity as well as wallets from which funds or associated account credentials were exfiltrated.
Japan’s campaign timeline
Japan’s National Police Agency said the campaign operated from about December 2025 through July 2026. Its Sept. 18 notice identified web designers, engineers and cryptocurrency or Web3 specialists among the intended targets.
The Japanese timeline places the activity over roughly eight months before the FBI and partner agencies quantified the wider infection and wallet-compromise figures. No further enforcement action, victim-recovery process or follow-up deadline was announced in the supplied advisories.