North Korea-Linked Hackers Used Fake Jobs to Steal Crypto

摘要:A North Korea-linked hacking group used fake job offers to target IT workers and steal cryptocurrency, Japans NPA said Friday. The group, known as

A North Korea-linked hacking group used fake job offers to target IT workers and steal cryptocurrency, Japans NPA said Friday.

The group, known as WaterPlum, infected more than 30,000 devices across over 100 countries from December 2025 through July 2026. Investigators also found information linked to more than 7,000 crypto wallets.

At least ¥1.7 billion in cryptocurrency later moved to wallets controlled by the group, according to the NPA.

Fake Jobs Target IT Workers

WaterPlum posed as recruiters for companies working in AI, crypto and NFTs. Attackers contacted developers through social media, job websites and freelance platforms before sending technical interviews or coding assignments.

Discover more

News

Try CAD Software

NEWS

Some applicants received development files or projects and were asked to run code while completing the tasks. The NPA said attackers embedded malicious code in some files, allowing malware to access information stored on victims computers.

The malware could collect browser credentials, keystrokes, screenshots and clipboard data. It also targeted crypto wallet information, private keys, seed phrases and identity documents.

NPA Warns of North Korean Links

The NPA, FBI and other agencies linked WaterPlum‘s activity to North Korean operations. They also identified “laptop farms” where North Korean IT workers remotely operated computers at intermediaries’ locations.

The NPA urged companies to verify workers identities, employment histories and locations. It also advised developers to test unfamiliar code in isolated environments.

Related: Crypto Tracing Helps UAE and Sweden Bust $7 Million Laundering Ring

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

研究员利用 Claude 攻破 OpenAI 获 6500 美元

下一篇

每周编辑精选 Weekly Editor's Picks ( 0912-0918 )