CNN Türk19 EYLÜL AKARYAKIT FİYATLARI | Motorin (mazot) ve benzine zam ya da indirim geldi mi? İstanbul, Ankara, İzmir güncel yakıt pompa fiyatlarıThe Jerusalem PostShroud displaying names of 20,000 Palestinian children unveiled at UN’s NY headquarters - reportPunchSoldiers rescue six kidnapped victims in Kaduna, KatsinaRTP DesportoWarren comanda na Aroeira, portugueses lutam pela subidaESPNOregon wins in 84-0 rout despite missing 2 key players on offense한겨레“규칙 지킨 사람만 불이익”…수험생들 “마감 후 원서 전면 취소하라”InquirerSouth Cotabato solon calls for stronger school safety measuresBollywood HungamaYeh Prem Mol Liya: Himesh Reshammiya to launch title track of Ayushmann Khurrana, Sharvari starrer live with 25-piece orchestra on September 20Inquirer EntertainmentBTS closes 2026 iHeart Radio Music Festival Day 1 with fiery setХабрДемон Сциларда: Энтропия и информацияSözcüYargıtay'dan yeni nafaka kararı: Bu şartları taşıyanlar artık alamayacakCNN بالعربيةالحرس الثوري يضع شرطا بشأن تصدير النفط من أي دولة بالمنطقة
The Daily Newsstand · Free, Always
Saturday, September 19, 2026

North Korean hackers behind crypto thefts across 100 countries, including Japan

Translate

A North Korean hacker group was behind a cyberattack spanning more than 100 countries, including Japan, that led to the theft of cryptocurrency worth about ¥1.7 billion, the National Police Agency has said.

The North Korean group, called WaterPlum, infected more than 30,000 devices with malware between December last year and July this year, stealing credentials for around 7,000 cryptocurrency accounts, according to a warning document released Friday.

Signed by seven organizations from four countries, including the NPA and the U.S. Federal Bureau of Investigation, the document was released under a framework called “public attribution,” aimed at deterring cyberattacks by revealing groups or government agencies behind such attacks.

The NPA said that WaterPlum posed as corporate headhunters recruiting information technology professionals, sending malware-infected files disguised as technical assessments to steal victims’ crypto-asset account credentials. At least ¥1.7 billion worth of cryptocurrency was transferred to accounts controlled by the group, with much of it believed to have come from compromised accounts.

The report also confirmed that North Korean IT workers living in North Korea, China and Russia earned foreign currency by taking on remote programming jobs and other work under false identities. As a result, hundreds of millions of yen had been transferred to North Korea in recent years.

These activities were backed by supporters residing in Japan, who provided the computers and servers utilized for such operations, as well as their own identification documents and financial accounts. The NPA said that Japanese police had dismantled the network through their investigation.

Additionally, the report stated that the IP addresses used by WaterPlum in the malware cyberattack matched those used for foreign currency-earning activities and job applications.

The NPA and the FBI indicated that both WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which is responsible for weapons development and IT strategy under the Central Committee of the Workers Party of Korea.

View the original on The Japan Times

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.