深潮TechFlow
深潮TechFlow|Sep 18, 2026 12:36
North Korean cyber attack group 'WaterPlum' launches large-scale attack on IT technicians According to TechFlow, on September 18th, the Japanese Police Agency, in collaboration with FBI, ASD/ASCS, BND, and BfV, issued an alert stating that the North Korean background network attack organization "WaterPlum" (also known as Contagious Interview) targeted job seekers by disguising themselves as AI, encrypted assets, and NFT companies to release false job postings, inducing job seekers to download NPM packages containing malicious software such as BeaverTail, InvisibleFerret, OtterCookie, and stealing encrypted asset wallet information and confidential data. As of July 2026, the organization has infected over 30000 devices in more than 100 countries and regions worldwide, stolen over 7000 pieces of encrypted asset wallet information, and its controlled wallets have received at least approximately 1.7 billion yen (approximately 10.71 million US dollars) in encrypted assets. For the first time in Japan, the National Police Agency discovered and destroyed a "laptop farm" set up by local "supporters". North Korean IT workers remotely operated PCs in the supporters' residences to carry out business, involving billions of yen in related cases. The police department and FBI have assessed that WaterPlum and some North Korean IT workers are under the unified command of the 313 General Bureau of the Military Supply Industry Department of the Central Committee of the Workers' Party of Korea, and the profits obtained directly flow into the North Korean national fund pool. The police remind IT technicians and corporate issuers to be vigilant and avoid executing third-party code in unverified environments, and to remain highly vigilant against applicants who insist on remote work and encrypted asset payments during the recruitment process.
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads