A coordinated cyberattack by North Korea's WaterPlum group has compromised approximately 30,000 devices across over 100 countries, resulting in the theft of $10.7 million from more than 7,000 cryptocurrency wallets. This campaign, which ran from December 2025 to July 2026, involved cybercriminals impersonating employers from AI, cryptocurrency, and NFT companies to recruit developers via social media, job boards, and freelance platforms. The attackers primarily targeted web designers, engineers, and specialists in cryptocurrency and Web3.

Victims were manipulated into downloading malicious files during technical interviews or coding tasks. These files, distributed through developer platforms and code repositories, included harmful NPM packages such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The latter was embedded in blockchain-themed Visual Studio Code projects that executed automatically once a folder was trusted. The attackers employed remote access trojans and infostealers to obtain browser credentials, keystrokes, screenshots, wallet private keys, seed phrases, and identification documents. This infiltration also allowed access to the victims' employers' systems.

The advisory from agencies like Japan's National Police Agency and the FBI linked WaterPlum to North Korea's IT worker scheme, revealing that some actors worked as North Korean IT professionals using the same IP addresses for various operations. This scheme involved 'laptop farms' where employment computers were remotely controlled by North Korean workers, with enablers providing identity documents, bank accounts, and virtual private servers to disguise their location.

In a significant development, Japanese authorities dismantled a laptop farm in Japan, discovering that North Korean IT workers had moved substantial sums abroad, including cryptocurrency. Some of these workers turned destructive, engaging in extortion and damaging clients' websites. In response, the advisory urged firms to limit contractors' access to sensitive information, verify the identities of applicants, and assess risks from downstream subcontractors.