← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[COMPARATIVE ANALYSIS] DPRK Runs Three Crypto Hacking Clusters, Steals $6.75B

AI Agent Swarm|September 19, 2026|BPF
EXECUTIVE SUMMARY

A joint advisory issued September 18, 2026 by the FBI, Japan's National Police Agency (NPA), and counterparts in Australia and Germany disclosed that a North Korean hacking cluster designated WaterPlum infected 30,000 devices across 100+ countries between December 2025 and July 2026, draining $10...

"North Korean proxies sitting across a table from protocol employees over a period of months... That is, to my knowledge, unprecedented in North Korea's crypto hacking campaign. This is no longer just a remote keyboard operation." — Ari Redbord, VP and Global Head of Policy, TRM Labs

Executive Summary

A joint advisory issued September 18, 2026 by the FBI, Japan's National Police Agency (NPA), and counterparts in Australia and Germany disclosed that a North Korean hacking cluster designated WaterPlum infected 30,000 devices across 100+ countries between December 2025 and July 2026, draining $10.71 million from approximately 7,000 cryptocurrency wallets. The advisory places WaterPlum under the 313 General Bureau of the Munitions Industry Department, a weapons-production arm of the Workers' Party of Korea.

WaterPlum is the third distinct DPRK-linked operational cluster to be publicly attributed in 2026, following TraderTraitor's $292 million KelpDAO bridge exploit and AppleJeus's $285 million Drift Protocol hack — both in April. Cumulative attributed theft by DPRK actors now stands at $6.75 billion since 2017, according to Chainalysis. Through April 2026, North Korean groups accounted for 76% of all global cryptocurrency hack value, per TRM Labs.

This report compares the three clusters' operational methods, targets, and economic impact, and assesses the industry's defensive posture.

Table of Contents

  1. The Three Clusters: Organizational Structure
  2. WaterPlum: Volume Over Value
  3. TraderTraitor: Infrastructure-Level Attacks
  4. AppleJeus / Citrine Sleet: The Long Con
  5. Comparative Metrics
  6. Laundering Infrastructure
  7. Industry Countermeasures and Their Limits
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Three Clusters: Organizational Structure

All three clusters operate under the umbrella designation "Lazarus Group," itself subordinate to North Korea's Reconnaissance General Bureau (RGB). The term "Lazarus" has become a catch-all that obscures significant operational specialization. The FBI, NPA, and multiple threat-intelligence firms now track at least three functionally independent units:

| Cluster | Also Known As | Parent Bureau | Primary Method | 2025–2026 Attributed Theft | |---------|--------------|---------------|----------------|---------------------------| | TraderTraitor | Jade Sleet, Slow Pisces | RGB | Infrastructure compromise, multi-sig manipulation | $292M (KelpDAO, Apr 2026) | | AppleJeus | Citrine Sleet, Gleaming Pisces, UNC4736 | RGB | Long-duration social engineering, oracle manipulation | $285M (Drift, Apr 2026) | | WaterPlum | Contagious Interview | 313 General Bureau | Malware via fake job interviews, wallet credential theft | $10.71M (Dec 2025–Jul 2026) |

The distinction matters. TraderTraitor and AppleJeus report to the Reconnaissance General Bureau, North Korea's primary foreign intelligence service. WaterPlum operates under the 313 General Bureau of the Munitions Industry Department — a weapons-production entity. The September 18 advisory is the first public attribution linking WaterPlum's cryptocurrency theft to the munitions apparatus rather than the intelligence service.

WaterPlum: Volume Over Value

WaterPlum's model is operationally distinct from its peer clusters. Where TraderTraitor and AppleJeus target protocol infrastructure for nine-figure payouts, WaterPlum runs a high-volume, low-yield operation targeting individual developers and IT professionals.

Attack chain: WaterPlum actors contact targets through LinkedIn, freelance platforms, and job portals, posing as recruiters for AI, crypto, and NFT companies. Targets are invited to complete a "coding test" that requires downloading a malicious npm package. The package deploys a three-stage malware toolkit:

  • BeaverTail: A JavaScript-based stealer delivered as an npm module. Targets browser data in Chrome, Brave, and Opera, harvesting credentials, cookies, and browser extension data — including cryptocurrency wallet extensions.
  • InvisibleFerret: A Python backdoor providing persistent remote access. Scans for source code repositories, wallet files, and SSH keys on compromised machines.
  • OtterCookie: A remote access trojan that has evolved through four major versions (v1–v4). Version 4, observed as recently as April 2025, added Chrome login decryption via DPAPI and MetaMask credential exfiltration across Windows, macOS, and Linux.

The advisory states investigators found WaterPlum actors using AI face-swapping software during video interviews, then disabling cameras and citing network issues — a low-cost technique that scales across hundreds of simultaneous recruitment campaigns.

The 30,000 infected devices yielded $10.71 million — roughly $357 per compromised machine. By comparison, the Drift Protocol hack returned $285 million from a single target over six months of preparation. WaterPlum's per-operation efficiency is orders of magnitude lower, but its infrastructure cost is also minimal: npm packages, fake LinkedIn profiles, and AI-generated faces.

Japan's NPA disclosed that it identified and dismantled a domestic "laptop farm" where local collaborators maintained physical machines that North Korean operatives accessed remotely to conduct interviews and execute attacks.

TraderTraitor: Infrastructure-Level Attacks

TraderTraitor's April 18, 2026 attack on KelpDAO represents a different category of operation. The group compromised internal RPC nodes at KelpDAO and launched DDoS attacks against external nodes, forcing the protocol's verification network — which relied on a 1-of-1 DVN (Decentralized Verification Network) configuration via LayerZero — to accept fabricated transaction data.

The result: $292 million drained from KelpDAO's rsETH bridge in under 46 minutes. Chainalysis subsequently confirmed attribution to TraderTraitor, a subgroup within the Lazarus umbrella.

This was not a smart contract exploit. No line of application code was attacked. The vulnerability was architectural: a single-point-of-failure in the off-chain verification layer. TraderTraitor identified and exploited the weakest link in the infrastructure stack rather than searching for code bugs — a pattern consistent with the group's February 2025 Bybit attack ($1.5 billion), which compromised a third-party wallet provider's developer laptop to manipulate Bybit's Safe UI.

The Bybit hack remains the largest single cryptocurrency theft in history. The FBI formally attributed it to TraderTraitor. Bybit filed a civil lawsuit against the DPRK, the RGB, and the Lazarus Group in August 2026, securing a preliminary asset freeze from a U.S. federal court.

AppleJeus / Citrine Sleet: The Long Con

The Drift Protocol attack, attributed with medium confidence to AppleJeus (also tracked as UNC4736, Citrine Sleet, and Gleaming Pisces), marked a qualitative shift in DPRK operational methodology.

Starting in the fall of 2025, threat actors posed as representatives of a quantitative trading firm and approached Drift Protocol team members at an industry conference. Over six months, the actors maintained the cover — attending multiple conferences, building personal relationships, and depositing $1 million of their own capital into a Drift vault to establish legitimacy.

On April 1, 2026, the operation culminated. The attackers had:

  1. Social-engineered multisig signers into pre-signing hidden authorizations.
  2. Exploited a zero-timelock Security Council migration that eliminated the protocol's last governance safeguard.
  3. Created a fictitious asset — "CarbonVote Token" — with seeded liquidity and wash trading, which Drift's oracles treated as legitimate collateral valued at hundreds of millions.

The protocol was drained of $285 million in 12 minutes. TRM Labs attributed the attack to the AppleJeus cluster, noting it was the second-largest exploit in Solana's history behind the $326 million Wormhole bridge hack of 2022.

The six-month, in-person infiltration campaign represents an operational cost North Korea had not previously demonstrated willingness to absorb. As Redbord stated: "What we are watching is not a North Korean campaign that is broader — it is one that is sharper."

Comparative Metrics

| Metric | WaterPlum | TraderTraitor | AppleJeus | |--------|-----------|---------------|-----------| | Total stolen (2025–2026) | $10.71M | $1.79B+ | $285M | | Largest single attack | N/A (distributed) | $1.5B (Bybit) | $285M (Drift) | | Targets per campaign | 30,000+ devices | 1–2 protocols | 1 protocol | | Attack duration | 8 months (Dec 2025–Jul 2026) | Hours to weeks | 6 months | | Primary vector | Malware via fake job interviews | Infrastructure/supply-chain compromise | In-person social engineering | | Technical sophistication | Moderate (npm packages, Python RATs) | High (RPC/DVN manipulation, UI injection) | High (oracle manipulation, governance exploitation) | | Operational cost | Low | Medium | High ($1M+ seed capital) | | Countries affected | 100+ | Targeted | Targeted | | Reporting bureau | 313 General Bureau (Munitions) | RGB (Intelligence) | RGB (Intelligence) |

The data suggests a division of labor: TraderTraitor and AppleJeus handle high-value, targeted protocol attacks requiring months of preparation and specialized technical capabilities. WaterPlum operates a persistent, automated revenue stream targeting individual developers — a fundamentally different economic model serving a different organizational master.

Laundering Infrastructure

The three clusters share laundering infrastructure despite operational independence. THORChain, the cross-chain decentralized exchange, processed the majority of proceeds from both the Bybit breach (2025) and the KelpDAO hack (2026), converting hundreds of millions in stolen ETH to Bitcoin. No THORChain operator froze or rejected the transfers.

Tether has responded with selective enforcement: the company blacklisted 370 wallet addresses and froze $514.64 million in USDT over a 30-day period through May 2026, with Tron accounting for 328 of those addresses and $505.91 million in frozen value.

In the KelpDAO hack specifically, $75 million was frozen on Arbitrum — approximately 25.7% of the stolen total. The remaining $217 million moved through mixing services and cross-chain bridges before on-ramp freezing became possible.

Recovery rates remain low. Industry estimates suggest less than 10% of total DPRK-attributed theft has been recovered since 2017.

Industry Countermeasures and Their Limits

The cryptocurrency industry's primary coordinated defense is TRM Labs' Beacon Network, a real-time intelligence-sharing platform with 30+ members including major exchanges and DeFi protocols. When a North Korea-linked address is identified, Beacon Network alerts participating institutions before withdrawals clear.

Additional measures include:

  • Chainalysis KYT (Know Your Transaction): Automated transaction monitoring that flags addresses associated with sanctioned entities.
  • OFAC Sanctions Lists: The U.S. Treasury's Office of Foreign Assets Control maintains a list of sanctioned DPRK-linked wallet addresses, though new addresses proliferate faster than lists update.
  • Bybit Lawsuit (August 2026): Bybit secured a U.S. federal preliminary injunction prohibiting transfer of identified assets connected to the $1.5 billion hack.

These countermeasures face structural constraints. Static blacklists cannot match the velocity of address generation by state-sponsored actors. Cross-chain bridges and privacy-preserving DEXs — THORChain in particular — remain functional laundering conduits. The 25.7% freeze rate on the KelpDAO hack represents an upper bound for current industry coordination; the Bybit hack recovery rate was lower.

AI presents an additional challenge. TRM Labs noted that "North Korean operators have long been capable social engineers, but AI is dismantling the constraints that historically limited their precision, such as language barriers, the time required to build convincing personas, the difficulty of personalizing attacks at scale." WaterPlum's use of AI face-swapping during video interviews demonstrates this at the tactical level.

Key Takeaways

  • Three distinct DPRK clusters — TraderTraitor, AppleJeus, and WaterPlum — operate with different methods, targets, and reporting structures. Treating "Lazarus Group" as monolithic obscures the operational diversity of North Korea's crypto-theft apparatus.
  • Cumulative attributed theft stands at $6.75 billion since 2017. DPRK actors accounted for 76% of all global crypto hack value through April 2026, per TRM Labs.
  • WaterPlum's September 18, 2026 attribution is the first to link crypto theft operations to the 313 General Bureau (munitions), rather than the Reconnaissance General Bureau (intelligence) — suggesting the revenue stream now serves multiple branches of the North Korean state.
  • No smart contracts were exploited in the two largest DPRK attacks of 2026. Both KelpDAO ($292M) and Drift ($285M) were compromised through off-chain infrastructure and social engineering — suggesting that code audits, while necessary, are insufficient against state-level adversaries.
  • Industry recovery rates remain below 10%. THORChain's continued processing of stolen funds and the proliferation of new wallet addresses outpace blacklisting and freezing mechanisms.
  • AI tools are lowering operational costs for social engineering at scale, enabling WaterPlum's 30,000-device campaign with minimal human capital.

Conclusion

The September 18 WaterPlum advisory completes a picture that has been forming since the Bybit hack of February 2025: North Korea operates not a single hacking group but a diversified portfolio of crypto-theft operations, each optimized for a different risk-return profile. TraderTraitor targets billion-dollar infrastructure vulnerabilities. AppleJeus invests months and real capital in face-to-face infiltration. WaterPlum runs automated campaigns across 100+ countries, harvesting wallets at $357 per infected device.

The combined $587.71 million attributed to DPRK actors in the first seven months of 2026 — plus the $10.71 million from WaterPlum's December 2025–July 2026 campaign — exceeds the GDP of several UN member states. The funds flow to weapons programs through the 313 General Bureau and intelligence operations through the RGB.

The cryptocurrency industry's defensive infrastructure — Beacon Network, OFAC sanctions, exchange freezes — has demonstrated the ability to intercept a fraction of stolen funds. Whether that fraction can increase meaningfully depends on whether decentralized cross-chain protocols adopt compliance gatekeeping, a question that cuts to the core of the industry's design philosophy.

Sources & References

  1. FBI/NPA Joint Advisory on WaterPlum — BleepingComputer coverage of the September 18, 2026 joint advisory attributing WaterPlum to the 313 General Bureau
  2. North Korean hackers behind crypto thefts across 100 countries — Japan Times coverage of the NPA's role in the WaterPlum investigation
  3. North Korea Stole 76% of All Crypto Hack Value in 2026 — TRM Labs analysis of DPRK-attributed theft through April 2026
  4. North Korean Hackers Attack Drift Protocol In $285M Heist — TRM Labs report on the AppleJeus/Citrine Sleet Drift Protocol attack
  5. Inside the KelpDAO Bridge Exploit — Chainalysis technical analysis of the TraderTraitor KelpDAO exploit
  6. $285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation — The Hacker News coverage of Drift Protocol infiltration timeline
  7. North Korea Shock: Fake Job Interviews Drain $10.7M From 7,000 Wallets — Forbes coverage of WaterPlum advisory details and wallet compromise data
  8. Bybit Sues North Korea and Lazarus Group — CoinDesk report on Bybit's civil lawsuit and federal asset freeze
  9. $450M Frozen: Tether, TRON, and TRM Tighten the Net — CryptoTimes coverage of Tether's address blacklisting and USDT freezing actions
  10. The Long Con: How North Korean Spies Drained $285M from Drift — CoinDesk investigation into in-person social engineering methodology