Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

cyberscoop+1pcmag+1cyberscoop+1A North Korean hacking group infected more than 30,000 devices across over 100 countries by posing as recruiters for AI and cryptocurrency firms, stealing credentials from over 7,000 cryptocurrency wallets and looting at least $10.7 million, according to a joint advisory issued Friday by security agencies in the United States, Japan, Australia and Germany.cyberscoop+1
The group, tracked as WaterPlum and also known as Contagious Interview, targeted software developers, web designers and specialists in cryptocurrency, blockchain and Web3 technologies between roughly December 2025 and July 2026, the FBI and Japan's National Police Agency said.nippon+1
WaterPlum operators approached victims through social media, online job platforms and freelance marketplaces, impersonating legitimate AI, cryptocurrency and NFT companies. During fake interview processes, candidates were instructed to download files presented as coding assignments or technical assessments. Opening these files installed malware including BeaverTail, InvisibleFerret, OtterCookie and other variants that gave attackers persistent backdoor access.pcmag+1
Once inside, the attackers harvested browser credentials, keystrokes, clipboard data, private keys and seed phrases for cryptocurrency wallets, as well as identity documents such as passports and driver's licenses. Stolen identities were then recycled to support further impersonation by North Korean IT workers seeking remote employment at legitimate companies.crypto+1
The advisory attributed WaterPlum to the 313 General Bureau of the Munitions Industry Department, a body linked to North Korea's nuclear weapons and missile programs. Authorities said the overlap between WaterPlum's cyber operations and North Korea's broader IT worker fraud scheme was substantial, with both campaigns sharing IP addresses used to access laptop farms and crowdsourcing services.crypto+2
Japanese investigators dismantled the first known domestic laptop farm connected to North Korean IT workers, where a local facilitator maintained computers that were remotely controlled by workers overseas. Authorities said hundreds of millions of yen in cryptocurrency had been transferred out of Japan through these arrangements. A suspected North Korean worker also attempted to secure an engineering position at cryptocurrency exchange bitFlyer in 2025 but was identified before being hired.cyberscoop+1
The advisory arrives alongside a report from the Multilateral Sanctions Monitoring Team exposing thousands of North Korean nationals employed in industries worldwide. Researchers estimate roughly 100,000 North Korean IT workers are employed or seeking work globally, with the sprawling fraud operation thought to generate upwards of $500 million annually for Pyongyang.theregister+1
The FBI urged IT job seekers to avoid executing code from untrusted third parties, run unknown code only inside sandboxes or virtual machines, and immediately disconnect any compromised device from the internet.pcmag