
Joint international advisory details how North Korean operatives posing as recruiters infected 30,000 devices globally.
AI-generated summary
North Korea utilizes remote IT workers and hacking groups to generate revenue for the state, often bypassing international sanctions.
A North Korean crew that poses as recruiters to compromise developers has taken funds or credentials from more than 7,000 cryptocurrency wallets and moved around $10.71 million to Pyongyang, seven agencies across four countries said in a joint advisory published on September 18.
The group, which Japan's National Police Agency calls WaterPlum and the security industry knows as Contagious Interview, infected at least 30,000 devices in more than 100 countries between roughly December 2025 and July 2026. Targets were web designers, engineers and specialists in crypto, blockchain and Web3 work.
It is signed by Japan's National Police Agency and National Cybersecurity Office, the FBI and the U.S. Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND foreign intelligence service and BfV domestic security agency.
The NPA and the FBI assess that both WaterPlum and some of North Korea's remote IT workers report to the 313 General Bureau of the Munitions Industry Department, which sits under the Workers' Party central committee. The two operations also used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs, which the agencies treat as evidence the two are one operation.
North Korea's hacking campaign
Actors impersonate AI, crypto or NFT companies, approach developers through social media, job boards and freelance marketplaces, then set a technical interview or coding task. Candidates are told to download files from developer platforms, either to finish the assignment or to fix an apparent fault in the video call. The advisory names five malware families carried in those packages, among them BeaverTail, InvisibleFerret and StoatWaffle, the last of which hides in blockchain-themed repositories.
The advisory also logs what investigators observed of the crew itself. Members used AI face-swapping software in interviews before cutting video and asking the candidate to do the same, blaming the connection. They practised Japanese pronunciation with text-to-speech tools, worked consistently on free machine-translation and AI tiers, and on holidays celebrated in North Korea played games and watched soccer videos instead of running their usual operations.
Japanese authorities also identified and dismantled a laptop farm run by a domestic enabler, the first such case in the country, finding evidence that several hundred million yen in crypto had moved abroad. A laptop farm is usually an enabler's home, where work computers are run remotely by IT workers in North Korea, China or Russia.
A Japanese crypto exchange turned away an applicant in May 2025 whose résumé claimed implausibly broad skills and whose English did not match the record. Other tells include refusing to meet in person, asking to be paid in crypto, and glancing repeatedly at a second screen.

European Union financial regulators warn that future quantum computing advancements could compromise blockchain cryptography. While no current computer can execute such attacks, major networks like Bitcoin and Ethereum are already considering mitigation strategies.

Microsoft and Coinbase dismantled EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 inboxes across 10,000 organizations. UK police arrested two suspects following investigations into the $1.1 million operation.

Zcash users holding ZEC in the legacy Sprout shielded pool must move their funds before the planned NU7 upgrade or risk losing spending access, according to a community proposal.

A malicious iOS app named FomoPeek, distributed through Apple's App Store, was found to contain kernel exploits that stole nearly $580,000 in cryptocurrency by accessing wallet data and Keychain information, according to a SlowMist investigation with OKX security team.

XRP Ledger validators have conditionally activated the BatchV1_1 amendment for Sept. 29 at 14:06:41 UTC, converting a previously identified security flaw into a live test of the network's amendment process. The fix addresses a critical authorization vulnerability that could have allowed unauthorized transactions if activated on mainnet. Activation depends on maintaining over 80% validator support for two weeks, with current support at 30 of 35 trusted validators. The update enables atomic transaction flows while requiring client software upgrades to avoid consensus disruption.

Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman are expected to brief the UN Security Council on Wednesday on AI risks and international security implications, with Hugging Face CEO Clément Delangue and Yoshua Bengio also participating. Chinese AI firms DeepSeek and Moonshot have been invited to speak, though DeepSeek's founder will not attend. France is convening the meeting as global concerns grow over advanced AI systems and potential loss of human control.