Tag: North Korean hackers

  • North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    North Korean fake recruiters infect 30K devices, steal $10.7M in crypto

    Key Highlights

    • North Korean hacking group WaterPlum, also known as Contagious Interview, stole at least $10.7 million by impersonating recruiters from legitimate crypto and AI companies to target software developers and IT professionals worldwide.
    • The campaign infected over 30,000 devices across more than 100 countries and extracted funds or credentials from over 7,000 cryptocurrency wallets between December 2025 and July 2026.
    • A joint advisory from Japan, Germany, Australia, and the United States links WaterPlum to North Korea’s Munitions Industry Department and its broader strategy of placing undercover IT workers inside foreign organizations.

    Global Advisory Exposes Sophisticated Recruitment Fraud

    A joint cybersecurity advisory issued by authorities in Japan, Germany, Australia, and the United States has detailed a sprawling operation by the North Korean hacking group WaterPlum, also tracked as Contagious Interview. The group masqueraded as recruiters for legitimate artificial intelligence, cryptocurrency, and non-fungible token (NFT) companies, leveraging social media platforms, online job boards, gig work sites, and freelance marketplaces to lure victims. According to the advisory, the primary targets were individual web designers, engineers, and specialists in cryptocurrency, blockchain, and Web3 technologies. The operation has resulted in the theft of at least $10.7 million, marking a significant escalation in North Korea’s use of social engineering to fund its weapons programs.

    Malware Deployment via Fake Coding Assignments

    The attack chain relied on tricking job seekers into downloading and executing malicious files disguised as coding assignments or fixes for video-conferencing errors. Once executed, the malware provided the threat actors with backdoor access to the victim’s computer. WaterPlum operators then deployed remote-access trojans and infostealing malware to exfiltrate sensitive data and cryptocurrency. The advisory notes that successful infections create downstream risks, enabling WaterPlum actors to infiltrate the organizations that employ the compromised developers, thereby extending the blast radius beyond individual freelancers to corporate networks.

    Connection to North Korean IT Worker Infiltration

    The advisory explicitly links WaterPlum’s activities to North Korea’s broader campaign of placing IT workers inside foreign companies under false pretenses. Japanese and U.S. authorities assess that WaterPlum actors and certain North Korean IT workers operate under the direction of the country’s Munitions Industry Department. This dual-track approach—stealing cryptocurrency directly while simultaneously building a workforce of impersonators—amplifies the regime’s revenue generation. Stolen identity documents allow North Korean operatives to impersonate legitimate developers, securing employment and income, while sensitive personal data harvested during intrusions creates opportunities for extortion.

    Recent Incidents Highlight Ongoing Threat

    The advisory cites concrete examples of the infiltration tactic. In one case, a suspected North Korean IT worker applied for an engineering role at a Japanese cryptocurrency exchange using a forged resume; the applicant was rejected after failing to demonstrate the claimed skills during the interview. More recently, in July, Cointelegraph reported that blockchain software company Consensys had unknowingly engaged a North Korea-linked developer as a consultant. Consensys confirmed it terminated the contractor’s access upon discovering the threat, stating an investigation found no theft of assets or data, no malicious code deployment, and no impact on user safety. These incidents underscore the persistent difficulty organizations face in vetting remote technical talent.

    Why This Matters

    The WaterPlum campaign represents the latest evolution in North Korea’s long-standing reliance on cryptocurrency theft to circumvent international sanctions and fund its nuclear and ballistic missile programs. The Federal Bureau of Investigation (FBI) previously attributed the $1.5 billion theft from the Bybit exchange in February 2025 to North Korean actors. U.S. authorities have issued warnings about the regime’s undercover IT worker scheme since at least 2018. The convergence of direct financial theft, supply chain compromise via compromised developers, and strategic workforce infiltration signals a mature, well-resourced threat ecosystem. For the cybersecurity industry and any organization hiring remote technical talent, the advisory serves as a critical reminder that identity verification and device trust cannot be assumed based solely on a resume or interview performance.

    Frequently Asked Questions

    What is WaterPlum and how does it operate?

    WaterPlum, also known as Contagious Interview, is a North Korean state-sponsored hacking group. It operates by posing as recruiters from legitimate AI, crypto, and NFT companies on job platforms. The group tricks software developers and IT professionals into downloading malware disguised as coding tests or software fixes, gaining backdoor access to steal cryptocurrency, credentials, and sensitive data.

    How can job seekers protect themselves from such recruitment scams?

    Job seekers should verify the legitimacy of recruiters and companies through independent channels before downloading any files. Be wary of unsolicited offers, requests to execute code as part of an interview process, or pressure to install specific video-conferencing software or “fixes.” Use endpoint detection and response (EDR) solutions and maintain strict separation between personal and work devices.

    What are the implications for companies hiring remote developers?

    Companies face the risk of inadvertently hiring North Korean operatives using stolen identities, which can lead to intellectual property theft, infrastructure compromise, and regulatory violations. The Consensys incident demonstrates that even sophisticated firms can be deceived. Organizations must implement rigorous identity verification, background checks, technical assessments that cannot be easily faked, and continuous monitoring of contractor activity.

  • Japan’s National Police Agency Exposes North Korean Hackers in Joint Operation with US, Australia, Germany

    Japan’s National Police Agency Exposes North Korean Hackers in Joint Operation with US, Australia, Germany

    Key Highlights

    • A seven-nation intelligence coalition publicly attributed a global cryptocurrency theft campaign to the North Korean group WaterPlum (alias “Contagious Interview”), linking the operation to the 313 General Bureau of the Munitions Industry Department under the Central Committee of the Workers’ Party of Korea.
    • Fake job recruitment schemes targeting software developers compromised over 30,000 devices across 100+ countries and breached approximately 7,000 cryptocurrency accounts, diverting an estimated 1.7 billion yen ($10.71 million) to North Korea between December 2025 and July 2026.
    • Japanese authorities dismantled a domestic “laptop farm” used to conceal the physical location of North Korean IT workers, marking the first such intervention in Japan and exposing a broader labor fraud network routing hundreds of millions of yen annually to Pyongyang.

    Seven-Agency Coalition Unmasks WaterPlum Operation

    In a coordinated announcement on Friday, September 18, 2026, seven national security agencies jointly exposed a North Korean cyber operation that has been masquerading as technology recruiters to steal cryptocurrency from information technology professionals worldwide. The advisory bears the seals of Japan’s National Police Agency (NPA) and National Cybersecurity Office, the United States Federal Bureau of Investigation (FBI) and Department of Defense Cyber Crime Center (DC3), Australia’s ASD Cyber Security Centre, and Germany’s Bundesnachrichtendienst (BND) and Bundesamt für Verfassungsschutz (BfV).

    The disclosure was made under a “public attribution” framework—a deliberate diplomatic and legal strategy designed to deter future attacks by formally naming the state sponsor and operational units behind malicious cyber activity. According to the joint assessment of the NPA and FBI, the hackers operating under the WaterPlum banner, alongside a contingent of North Korean IT workers, operate under the direct command of the 313 General Bureau of the Munitions Industry Department, a subunit of the Central Committee of the Workers’ Party of Korea. This chain of command confirms the operation as a state-directed revenue generation program for Pyongyang’s weapons development, a charge U.S. intelligence agencies have leveled repeatedly in previous North Korean cryptocurrency theft campaigns—allegations the North Korean regime has consistently denied.

    Fake Recruitment Lure: How the Malware Campaign Worked

    The threat actors posed as hiring managers at artificial intelligence firms, cryptocurrency ventures, and non-fungible token startups, extending attractive job offers to software developers. Candidates were guided through technical interviews or coding assignments, then instructed to download and execute files framed as assessment tasks. Those files were weaponized: they carried malware embedded in Node Package Manager (npm) packages, deploying a suite of custom payloads identified as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

    Once installed, the malware established persistent backdoors via remote-access trojans, enabling operators to harvest browser-stored passwords, keystroke logs, screenshots, and—critically—the private keys and seed phrases that control cryptocurrency wallets. Between December 2025 and July 2026, the campaign infected more than 30,000 devices in over 100 countries and compromised sensitive credentials for roughly 7,000 cryptocurrency accounts, yielding the 1.7 billion yen ($10.71 million) in diverted assets.

    Malware Arsenal and Technical Infrastructure

    The five identified malware families represent a modular toolkit designed for credential theft, system surveillance, and long-term access maintenance. Researchers note the use of legitimate software supply chains—specifically the npm registry—as a delivery vector, allowing the malicious packages to blend with routine development workflows. The stolen private keys and seed phrases provided direct, irreversible control over victims’ on-chain assets, facilitating rapid liquidation and laundering through North Korea’s established cryptocurrency mixing and exchange networks.

    Japan’s First Laptop Farm Takedown

    The advisory reveals a second, parallel operation: North Korean IT workers residing in North Korea, China, and Russia fraudulently secured remote programming and web-development contracts, funneling hundreds of millions of yen in wages back to the regime over several years. To obscure the true geographic origin of this labor, the network enlisted local facilitators to operate “laptop farms”—physical locations housing devices that made the remote workers appear to be logging in from within the hiring country.

    Japanese investigators identified, raided, and shut down one such laptop farm operated by a domestic enabler, marking the first known disruption of this infrastructure type in Japan. The takedown illustrates how North Korea’s revenue generation blends cyber intrusion with labor fraud, exploiting the global shift toward remote work to bypass sanctions and financial controls.

    Why This Matters

    The WaterPlum attribution arrives amid a sharp escalation in state-sponsored cryptocurrency theft. The advisory cites a 420% surge in malware targeting public blockchains, with North Korea and Iran identified as primary originators. In June 2026, G7 leaders formally classified North Korean cryptocurrency theft as a significant security threat, citing an estimated $6.75 billion stolen since 2016 by Pyongyang-linked actors. Independent research presented at Black Hat by Vangelis Stykas corroborates the scale: his analysis traced North Korean infiltration into 1,640 companies across 57 countries, frequently initiated through the same fake job offers that deliver malware, as reported by Cryptopolitan. The seven-agency public attribution signals a strategic shift toward collective deterrence, exposing not only the hackers but the institutional command structure that directs them.

    Frequently Asked Questions

    What is WaterPlum and who controls it?

    WaterPlum (also known by the alias “Contagious Interview”) is a North Korean cyber operation attributed by seven national intelligence agencies to the 313 General Bureau of the Munitions Industry Department, a unit under the Central Committee of the Workers’ Party of Korea. The group conducts cryptocurrency theft and labor fraud to fund North Korea’s weapons programs.

    How did the fake job scheme steal cryptocurrency?

    Attackers posed as recruiters at AI, crypto, and NFT companies. After interviews, victims were sent malware-laced npm packages (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) disguised as coding tests. The malware installed remote-access trojans, stealing browser passwords, keystrokes, screenshots, and—most critically—private keys and seed phrases for cryptocurrency wallets, enabling direct asset theft.

    What is a “laptop farm” and why is Japan’s takedown significant?

    A “laptop farm” is a physical facility where local enablers host devices that make North Korean remote workers appear to be logging in from within the hiring country (e.g., Japan). Japan’s disruption of such a farm is the first known case of its kind in the country, exposing a key infrastructure layer that allows North Korea to evade sanctions and labor laws while routing wages back to the regime.

  • North Korean Hackers Move Tens of Millions on Hyperliquid as Trump Pushes to Bring Crypto Platform Onshore

    North Korean Hackers Move Tens of Millions on Hyperliquid as Trump Pushes to Bring Crypto Platform Onshore

    Kraken said compliance is central to its operations and that it uses blockchain analytics partnerships to monitor onchain activity and block assets linked to sanctioned wallets before they reach the exchange. A representative for Kraken told CoinDesk that “compliance is foundational to how we operate. Kraken maintains a best-in-class compliance program, including partnerships with leading blockchain analytics providers that continuously monitor onchain activity. These controls are designed to identify and block any assets associated with sanctioned wallets before they enter our platform.”

    LBank said it has consistently relied on industry-standard compliance tools for ongoing monitoring. However, the exchange acknowledged that the crypto industry is “inherently cross-platform, cross-chain, and cross-jurisdictional.”

    “As a result,” the spokesperson added, “relevant risks are often not generated by, or capable of being independently identified and addressed by, any single platform, but instead represent an ongoing challenge faced by the industry as a whole.”

    KuCoin said it could not verify or comment on the sanctioned-wallet activity without reviewing the underlying data. CoinDesk declined to provide that data before publication.

    “We would also note that public onchain data reflects the movement of assets but does not necessarily provide a complete picture of compliance actions taken by a centralized platform after assets reach the platform. Measures such as account restrictions, regulatory reporting, or other risk-control actions may occur at the account or platform level and may not be visible from public blockchain data alone,” the representative said, adding that the exchange “maintains sanctions compliance policies and procedures designed to meet applicable legal and regulatory requirements.”

    Lazarus Group’s Hyperliquid activity

    The Lazarus Group’s use of Hyperliquid could expose the platform to scrutiny from authorities if it violates U.S. sanctions laws. The activity comes as the Trump administration considers how Hyperliquid could be integrated into the regulated U.S. financial system.

  • Lazarus Group Resurfaces With $19.4 Million Bitcoin Transfer

    Lazarus Group Resurfaces With $19.4 Million Bitcoin Transfer

    Bitcoin wallets linked to the North Korean hacking group Lazarus transferred 244.148 BTC worth approximately $19.42 million, renewing attention on the group’s ongoing cryptocurrency activity.

    Lazarus-linked wallets move 244.148 BTC

    Blockchain analytics firm Lookonchain reported the transfer in an Aug. 28 X post, saying wallets attributed to Lazarus Group had become active and moved 244.148 BTC about an hour before the alert.

    Bitcoin was trading at roughly $79,500 when Lookonchain published its estimate, placing the transaction’s value at about $19.42 million. The analytics firm did not identify the receiving address or say whether the Bitcoin was sent to an exchange, mixer or another wallet controlled by the group.

    Without a disclosed destination, the transfer alone does not prove that Lazarus sold the Bitcoin or attempted to cash out. Public blockchain records show when funds move between addresses, but attributing those addresses to an organization generally depends on labels and analysis from investigators or blockchain intelligence firms.

    The Aug. 28 movement followed another large Bitcoin transfer attributed to Lazarus earlier in the month. On Aug. 12, Lookonchain said the group moved 262.2 BTC, then worth approximately $16.64 million, from an identified wallet to a newly created address.

    At the time, Lookonchain described that transaction as a wallet-to-wallet transfer rather than a sale. Based on the reported dollar values, the two August transactions involved more than $36 million in Bitcoin. However, no source has confirmed that the funds came from the same balance or served the same purpose.

    Earlier wallet activity highlights why the destination of the latest transfer matters. In March 2025, five unknown addresses received a combined 44.07 BTC worth approximately $3.76 million from wallets attributed to Lazarus, according to previous on-chain reporting. The transactions reduced the tracked wallet’s holdings to 13,441 BTC at the time.

    Bybit theft spread Bitcoin across thousands of addresses

    As crypto.news previously reported, Bybit sued North Korea and Lazarus Group in a Washington, D.C., federal court on Aug. 7, seeking to recover assets linked to the exchange’s $1.5 billion theft.

    The lawsuit also named North Korea’s Reconnaissance General Bureau, or RGB, which the U.S. Treasury identifies as the country’s primary intelligence agency. A federal judge issued a preliminary injunction blocking unidentified defendants from transferring, selling or disposing of certain assets connected to the case.

    Bybit filed the civil lawsuit separately from ongoing U.S. criminal investigations. A preliminary injunction preserves identified property while litigation continues and does not represent a final ruling on ownership or liability.

    The FBI attributed the February 2025 Bybit attack to North Korean actors operating under the TraderTraitor name. According to the agency, the attackers converted part of the stolen holdings into Bitcoin and other assets before distributing them across thousands of addresses on multiple blockchains.

    In its public alert, the FBI said it expected the assets to be moved again and eventually exchanged for government-issued currency. The bureau asked exchanges, bridges, decentralized finance services, blockchain analytics companies and node operators to block transactions involving the addresses it identified.

    By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked, according to an August report on North Korea’s attack methods. The report said that distributing the assets across numerous Bitcoin wallets had made blockchain tracing more difficult.

    Lookonchain has not directly connected the latest 244.148 BTC transfer to the Bybit theft. No government agency or blockchain intelligence company cited in the available reporting has publicly identified the source of the coins involved in the Aug. 28 movement.

    Lazarus-linked crypto attacks continued into 2026

    Chainalysis estimated that North Korean hackers stole at least $2.02 billion in cryptocurrency during 2025, a 51% increase from the previous year. The firm estimated North Korea’s cumulative cryptocurrency theft had reached at least $6.75 billion by the end of that period.

    According to its December 2025 report, North Korean operations accounted for 76% of the value lost through attacks on crypto services during the year. Chainalysis said the attackers carried out fewer confirmed incidents but extracted larger amounts from successful breaches.

    The firm also found that North Korean operators increasingly targeted companies through impersonation and employee-access schemes. Some actors posed as job applicants to gain entry to crypto businesses, while others pretended to recruit for established Web3 and artificial intelligence companies, according to Chainalysis.

    Activity attributed to Lazarus continued in April 2026, when attackers drained approximately 116,500 rsETH worth about $292 million from KelpDAO’s LayerZero-based bridge. LayerZero attributed the attack with preliminary confidence to the Lazarus Group’s TraderTraitor unit.

    Chainalysis later said the attackers had compromised infrastructure that supplied blockchain information to LayerZero’s verification system. By feeding false data into the system, they caused an Ethereum contract to release assets even though no corresponding token burn had occurred on the source network.

    Rapid intervention blocked a second attempted theft worth approximately $95 million, according to Chainalysis. The Arbitrum Security Council also froze more than 30,000 ETH that investigators connected to the attacker’s subsequent transactions.

    By June, the KelpDAO attacker had moved approximately $220 million in unfrozen assets through privacy services, according to subsequent tracking data. The routes included THORChain, Wasabi, Tornado Cash and Umbra, while approximately $1.7 million remained in the original wallets.

    U.S. sanctions restrict dealings with Lazarus Group

    The U.S. Treasury’s Office of Foreign Assets Control sanctioned Lazarus Group in September 2019 under an executive order targeting the North Korean government. OFAC identified Lazarus, Bluenoroff and Andariel as state-controlled hacking groups connected to the RGB.

    Under the designation, property belonging to Lazarus that enters the United States or comes into the possession or control of a U.S. person must be blocked and reported to OFAC. Treasury regulations also generally prohibit Americans from conducting transactions with sanctioned entities unless authorized by the agency.

    The Treasury said Lazarus had targeted governments, financial institutions, media companies, manufacturers, infrastructure operators and cryptocurrency businesses through cyber theft, espionage and malware attacks. The department linked the group to the 2014 Sony Pictures breach and the WannaCry ransomware attack, which affected computers across at least 150 countries.

    U.S. authorities have also taken action against services used to process funds linked to the group. In 2022, the Treasury sanctioned the virtual currency mixer Blender.io after saying it had processed more than $20.5 million from the roughly $620 million Ronin Network theft. The FBI later attributed the Ronin attack to Lazarus Group and APT38.

    In August 2023, the FBI separately warned cryptocurrency companies about movements involving Bitcoin stolen by North Korean TraderTraitor actors. The agency said the group could attempt to cash out more than $40 million in Bitcoin and published six wallet addresses for private companies to investigate.