Interview coding = Wallet theft? North Korean hacker group WaterPlum recruitment scam exposed.

CN
1 hour ago
North Korean hacker group WaterPlum steals $10.7 million in cryptocurrency assets through fake recruitment.

Written by: Boaz Sobrado

Translated by: Luffy, Foresight News

The hackers from this country once stole $1.5 billion from Bybit exchange in one day, and for the past nine months, they have targeted relatively smaller objectives: sending fake job opportunities to programmers. Last Friday, the FBI and Japan's National Police Agency released relevant data, revealing that the hackers had infiltrated at least 30,000 devices in over 100 countries, stealing funds and credentials from more than 7,000 cryptocurrency wallets, resulting in a total profit of $10.7 million, which ultimately flowed to Pyongyang.

This 9-page warning document was jointly signed by seven agencies from Japan, the United States, Australia, and Germany. Japanese police call this disclosure model "public attribution," directly revealing the national entities behind the attacks to act as a deterrent. The hacker organization is codenamed WaterPlum, but is more commonly known in the cybersecurity industry by its alias "Contagious Interview." These agencies classify it as being part of the General Bureau 313 under North Korea's Ministry of State Security, which is reportedly also responsible for directing some fake remote IT personnel within North Korea.

"Help troubleshoot online video conferencing platforms"

This attack methodology is essentially a fake recruitment process. The warning document states that members of the WaterPlum organization disguise themselves as employers, using lucrative job opportunities as bait to target software developers and IT personnel worldwide, with the impersonated recruiting companies often being fictitious AI, cryptocurrency, or NFT firms.

Applicants are asked to complete coding tests or "help troubleshoot an issue on the online video conferencing platform," with the so-called repair tool being a compressed code package. Inside the package are several pieces of malware: BeaverTail, InvisibleFerret, OtterCookie, and a new type of malware called StoatWaffle. It hides within folders of blockchain-themed projects, and when developers open the folder in VS Code and click the "trust" button, the malware executes automatically.

Once the malware runs, it will copy passwords, log keystrokes, take screenshots, collect cryptocurrency wallet recovery phrases, and steal any identifiable passport photos that can be found. Yoon Auh, founder of Boltz Technologies and former VP of IT at Goldman Sachs, when asked on "On The Margin" podcast if there is any application that is more secure than the mobile operating system it runs on, stated, "If someone is determined to target you, it's hard to evade. Unless you swap out all your devices, there are almost no protective measures."

"They watch soccer games"

The warning document reveals, unusually, details about the attackers on the other end of the calls. Interviewers use AI face-swapping software and turn off their cameras a few minutes into the call, citing internet issues to ask applicants to do the same. They also practice their Japanese pronunciation using text-to-speech tools. Japanese police investigations found that during North Korea's national holidays, "attackers take time off to play games and watch soccer matches, pausing malicious attack activities."

This group of hackers also actively submits job applications. In May 2025, a Japanese cryptocurrency exchange received an engineer's job application. The applicant claimed to be born in Malaysia, residing in Finland, and graduated from a university in Europe, but their English proficiency did not match the educational and professional background described in their resume, leading to their non-selection.

The police also listed other identifying clues: job seekers requesting to be paid in cryptocurrency, frequently glancing at another monitor during the interview (as if reading a prompt), and background noise of others talking.

Japanese police also dismantled the first known "laptop farm" within Japan (note: a laptop farm refers to a batch of computers that are kept running 24/7 by local accomplices for overseas hackers to remotely operate under false identities). In a residential location, local accomplices keep several working computers on all year round, allowing North Korean hackers overseas to impersonate identity and take on remote outsourcing projects. According to reports from current events agencies, these local accomplices lent their identification documents and bank accounts, facilitating the outflow of hundreds of millions of yen in stolen funds from Japan. The warning shows that the WaterPlum hackers and this group of fake IT personnel used the same IP addresses.

"They also have their own KPIs"

For Pyongyang, $10 million is not considered a large sum. Data from TRM Labs indicates that in the first half of 2026, the total amount stolen by global cryptocurrency hackers was $972 million, of which $643 million was related to North Korea, most of which came from two attacks in April targeting Drift and KelpDAO. TRM Labs also noted that this statistic "is only a part of North Korea's cryptocurrency income," and does not account for profits from phishing attacks, social engineering attacks, or "the covert operations impersonating IT personnel." The warning released last Friday tracked this portion of gray income, averaging about $1,500 stolen from each deceived user's wallet, while the victims initially thought they were participating in a job interview.

Ido Sofer, founder of key management company Sodot, stated on the "On The Margin" podcast that these attackers are part of an organized institution. "They have KPIs to meet, established goals, go to the office to work, and have a complete operational strategy. Especially for state-level forces from North Korea, they invest considerable resources, aiming to achieve their goals by any means. Once a state-level entity sets its sights on an individual, it is nearly impossible to resist."

Dmitry Machikhin from BitOK analytics company, who tracked the stolen funds from Bybit, mentioned in an interview, "We have identified some addresses and wallets used by the Lazarus group to store stolen funds. But that is all we can do; we have no authority to apprehend anyone."

"Do not let a single compromised device evolve into a total system compromise"

Official agencies have a straightforward suggestion for all victims who have received a code package from recruiters: assume your wallet information has been compromised. "Create a new wallet on a brand new, independent device, transfer all assets into the new wallet, store the new recovery phrase offline, and then completely wipe the compromised old device."

Past discussions on cryptocurrency security mostly revolved around exchange risks, while this attack's source of risk was a personal laptop.

Auh's view is that one should prepare for an invasion in advance, rather than relying solely on building an impregnable protective wall. "We know that no system can withstand all attack paths. If a particular device has already been breached, do not allow this leak to spread, leading to the entire system's loss of integrity."

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink