North Korean Hackers Infect 30,000 Devices, Target 7,000 Crypto Wallets

Coinmama
fiverr


North Korean hackers infected 30,000 devices and stole data from 7,000 crypto wallets while targeting victims across 100 countries.

North Korea-linked hackers infected more than 30,000 devices and stole information from over 7,000 crypto wallets. Japan’s National Police Agency says the attacks were carried out against targets in over 100 countries from December 2025 to July 2026. The FBI and other foreign agencies aided the investigation.

The primary audience for WaterPlum (also called Contagious Interview) was IT professionals. The group targeted developers and others in the tech industry using fake job offers.

WaterPlum Uses Fake Jobs to Target Crypto Professionals

Japanese authorities say that WaterPlum reached out to job seekers via social media. It also leveraged online job sites, freelance websites, and gig-work platforms.

okex

The attackers were allegedly impersonating cryptocurrency, artificial intelligence, and NFT companies. They also pretended to be recruitment agencies to seem genuine.

Related reading: South Korea Eyes Law for Crypto Wallet Seizures.

Once they met, they were required to do coding tasks or technical interviews with the group. But these tasks may involve victims downloading malware.

The malicious files were found on online development platforms and code repositories. These files were then used by victims in technical assignments or software troubleshooting.

WaterPlum has been utilizing multiple malware families in these attacks. These were BeaverTail, OtterCookie, OtterCandy, InvisibleFerret, and StoatWaffle.

In addition, the malware might create access to infected computers. It might also take passwords, screenshots, what you type on the keyboard, and clipboard data.

The attackers also attacked cryptocurrency wallet information. This comprised private keys, seed phrases, and other delicate wallet information.

In the meantime, authorities discovered that wallets controlled by WaterPlum received at least $10.71 million in cryptocurrency. The National Police Agency in Japan estimated this to be about ¥1.7 billion.

The infections impacted over 30,000 PCs in over 100 countries and regions. The primary targets were Web designers, engineers, blockchain workers, and Web3 professionals.

North Korean IT Workers Used Laptop Farms

The investigation also revealed North Korean IT workers and local supporters. The workers are said to have used a remotely controlled computer in the supporters’ home.

The Japanese government called these facilities “laptop farms.” These types of arrangements enabled employees to conceal their true identities when working online.

Furthermore, some employees were on virtual private servers and crowdsourcing. They reportedly operated from North Korea, China, Russia, Africa, and Southeast Asia.

The investigation also uncovered a suspected North Korean IT worker that applied to bitFlyer. In May 2025, the applicant applied for a position in engineering at the Japanese cryptocurrency exchange.

The applicant allegedly applied using someone else’s identity information in the application. The person also used the recruitment website via VPN services.

Investigators noticed a few suspicious items during the interview. The applicant’s technical responses were unclear, even with extensive professional experience.

The applicant also refused to move to Japan and demanded that his salary be paid in cryptocurrencies. Moreover, voices of other people were allegedly heard in the interview.

Matching IP addresses were also discovered for WaterPlum and North Korean IT workers. One address was also linked to the bitFlyer recruitment activity.

The NPA and FBI believe that WaterPlum and some North Korean IT activities are connected to Bureau 313. This bureau is part of North Korea’s Workers’ Party Central Committee.

Lastly, authorities urged developers not to run unknown code on work computers. They also suggested using virtual machines and limited environments for new projects.





Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*