Home/World/Article
World

North Korean Hacker Group WaterPlum Targeted Crypto Accounts Across 100 Countries, Japan's NPA Says

World Pulse EditorialPublished 3 min read
North Korean Hacker Group WaterPlum Targeted Crypto Accounts Across 100 Countries, Japan's NPA Says

According to Japan's National Police Agency, a North Korean cyberattack group named WaterPlum infected over 30,000 devices globally, resulting in substantial cryptocurrency thefts, including in Japan.

A North Korean hacker group has been identified as the driving force behind a sophisticated cyberattack spanning more than 100 countries, including Japan, which resulted in the theft of approximately ¥1.7 billion in cryptocurrency. According to information released by Japan's National Police Agency (NPA), the malicious campaign targeted digital assets on a massive international scale.

The hacker group, designated as WaterPlum, successfully infected more than 30,000 electronic devices with malware between December of last year and July of this year. As a result of these widespread infections, the group managed to compromise and steal credentials for roughly 7,000 individual cryptocurrency accounts.

The alarming details of the campaign were made public through a warning document released on Friday. The document was formally signed by seven distinct organizations hailing from four different countries, including the NPA and the United States Federal Bureau of Investigation (FBI).

Authorities released the advisory under an international framework known as “public attribution.” This strategy is specifically designed to deter ongoing and future cyberattacks by explicitly revealing the government agencies or specific hacker groups orchestrating the malicious activity.

Detailing the mechanics of the operation, the NPA stated that WaterPlum routinely posed as corporate headhunters. In this guise, the hackers targeted information technology professionals by sending malware-infected files carefully disguised as technical assessments or recruitment evaluations.

Once the targets downloaded and opened these fraudulent files, the malware enabled the hackers to steal vital account credentials. At least ¥1.7 billion worth of cryptocurrency was subsequently transferred to accounts controlled directly by the WaterPlum group, with the vast majority believed to originate from compromised victim accounts.

Beyond direct crypto thefts, the joint investigative findings also shed light on related illicit financial activities. The report confirmed that North Korean IT workers residing abroad in countries such as China, Russia, and North Korea itself have been earning foreign currency by securing remote programming positions and other employment under false identities.

Through these clandestine remote work schemes, hundreds of millions of yen have been funneled back to North Korea over recent years. Investigators discovered that these operations relied heavily on a support network located inside Japan.

Local supporters residing in Japan allegedly provided the hackers and remote workers with essential infrastructure, including computers, servers, personal identification documents, and local financial accounts. The NPA announced that Japanese law enforcement agencies have successfully dismantled this domestic support network through their rigorous investigation.

Further connecting the disparate elements of the operation, the report noted that the internet protocol (IP) addresses utilized by WaterPlum during the malware cyberattacks matched those used by individuals carrying out foreign currency-earning remote job applications.

Law enforcement authorities in Japan and the United States have linked both the WaterPlum hacking collective and the network of North Korean IT workers to a specific state apparatus. According to the NPA and the FBI, these cyber operations operate under the 313 General Bureau of the Munitions Industry Department.

This bureau functions directly under the Central Committee of the Workers Party of Korea and is primarily responsible for overseeing weapons development and overarching information technology strategy for the regime.

More from the newsroom

Latest stories

Sources & attribution