7,000 Crypto Wallets Targeted as North Korean Hackers Infect 30,000 Devices

Changelly
Bybit


TL;DR:

  • Japan’s National Police Agency and the FBI confirmed the infection of over 30,000 devices and the theft of credentials from 7,000 wallets across more than 100 countries.
  • Addresses controlled by the attackers received at least 1.7 billion yen (approximately $10.71 million) between December 2025 and July 2026.
  • Law enforcement dismantled Japan’s first operational “laptop farm” linked to North Korean IT worker identity theft schemes.

More than 7,000 targeted crypto wallets resulted from a coordinated cyber-espionage campaign originating from North Korea after compromising tens of thousands of corporate and personal endpoints. Japan’s National Police Agency (NPA) and the United States Federal Bureau of Investigation (FBI) confirmed the findings this Friday, September 18.

The official report attributes the offensive to the threat group tracked as WaterPlum, also cataloged in intelligence reports as Contagious Interview. Technical investigations directly link these operations to Bureau 313, a unit subordinate to the Munitions Industry Department of the Workers’ Party of Korea.

Threat actors leveraged fake job offers aimed at software engineers and blockchain specialists. Through fraudulent recruitment pipelines, the attackers convinced candidates to download manipulated NPM packages and malicious software disguised as technical coding assessments or videoconferencing patches.

Binance

Once executed, the malicious file established persistent backdoors on the targeted machines. This remote access allowed attackers to exfiltrate web browser credentials, keystroke logs, screenshots, private keys, seed recovery phrases, and government-issued identification documents such as passports and driver’s licenses.

Crypto wallets under attack

Technical Scheme and Dismantling of Operational Infrastructure

Forensic records show that receiving wallets managed by the organization captured funds valued at 1.7 billion yen over the documented active window. This figure represents an average loss of approximately $1,500 per affected address—a pattern that, according to police analysis, demonstrates a broad sweep of retail holders rather than an attack aimed exclusively at major corporate depositors.

Simultaneously, Japanese authorities raided the first “laptop farm” uncovered within the country linked to these networks. Inside these facilities, local conspirators kept laptops connected within private residences to facilitate remote control from abroad and mask the attackers’ true physical locations.

Judicial filings indicate that a portion of the illicitly acquired earnings initially flowed into bank accounts belonging to Japanese residents before being converted into stablecoins and digital assets routed to offshore jurisdictions.

The joint advisory issued by Japan, the United States, Germany, and Australia highlights that the investigation remains active pending further asset identification and fund-freezing measures during upcoming international judicial cooperation procedures.

 



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*