Daily MaverickIN PICTURES: Memorial run in honour of Elizabeth ‘Tsontso’ Moselakgomo in Kempton Parkוואלהאם ושני ילדיה נהרגו ממתקפת כטב"מים רוסית על קייבThe Jerusalem PostExpansive exhibition in Jaffa gives Gaza border artists a chance to air their traumaInquirer2 nabbed over shooting incident in Oriental MindoroPunchPolice seek help to reunite lost child with family in AnambraCNN TürkHava Durumu (20-09-2026)한겨레9월21일 알림SözcüParalarını kurtarmak için iade kuyruğuna geçtiler: 15 Kasım'da dev yasak başlıyorColliderRyan Reynolds’ $176M Action Smash Is Officially Making Its Last Stand on NetflixFootball ItaliaBisseck reacts to Inter draw with Roma: ‘We know we can always turn a game around’Rappler‘Terribly sorry’: Wrong Korean anthem played in Asian Games hockeyHindustan Times SportAfter World Cup low, India start afresh at Asian Games with 13-1 demolition of Indonesia
The Daily Newsstand · Free, Always
Sunday, September 20, 2026

North Korean hackers behind crypto thefts across 100 countries, including Japan

Translate

A North Korean hacker group was behind a cyberattack spanning more than 100 countries, including Japan, that led to the theft of cryptocurrency worth about ¥1.7 billion, the National Police Agency has said.

The North Korean group, called WaterPlum, infected more than 30,000 devices with malware between December last year and July this year, stealing credentials for around 7,000 cryptocurrency accounts, according to a warning document released Friday.

Signed by seven organizations from four countries, including the NPA and the U.S. Federal Bureau of Investigation, the document was released under a framework called “public attribution,” aimed at deterring cyberattacks by revealing groups or government agencies behind such attacks.

The NPA said that WaterPlum posed as corporate headhunters recruiting information technology professionals, sending malware-infected files disguised as technical assessments to steal victims’ crypto-asset account credentials. At least ¥1.7 billion worth of cryptocurrency was transferred to accounts controlled by the group, with much of it believed to have come from compromised accounts.

The report also confirmed that North Korean IT workers living in North Korea, China and Russia earned foreign currency by taking on remote programming jobs and other work under false identities. As a result, hundreds of millions of yen had been transferred to North Korea in recent years.

These activities were backed by supporters residing in Japan, who provided the computers and servers utilized for such operations, as well as their own identification documents and financial accounts. The NPA said that Japanese police had dismantled the network through their investigation.

Additionally, the report stated that the IP addresses used by WaterPlum in the malware cyberattack matched those used for foreign currency-earning activities and job applications.

The NPA and the FBI indicated that both WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is responsible for weapons development and IT strategy under the Central Committee of the Workers Party of Korea.

View the original on The Japan Times

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.