Japan's NPA and FBI Warn of North Korean "WaterPlum" Hackers Using Fake Recruiting to Steal Crypto
AI مارکیٹ کا خلاصہ
Japan's NPA and the FBI detailed a North Korea'linked campaign using fake job interviews and poisoned code repositories to compromise Web3 developers, stealing credentials and draining 7,000+ wallets (>$10.71m). The focus shift from exchanges to individuals raises operational risk across the crypto stack, potentially tightening security practices, slowing developer activity, and increasing compliance and sanctions scrutiny around crypto-linked payments.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.94%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Original source: npa.go.jp. Compiled by Odaily Planet Daily (@OdailyChina). Translator: Asher (@Asher_0210).
Japan's National Police Agency (NPA) and the U.S. Federal Bureau of Investigation (FBI) said on Sept. 18 that a North Korean-linked hacking group known as WaterPlum (also called "Contagious Interview") has been running a long-term campaign that masquerades as recruiting and project collaboration to trick developers into executing malware.
Authorities said that from December 2025 to July 2026, the group infected more than 30,000 devices across over 100 countries and targeted more than 7,000 cryptocurrency wallets, stealing or enabling transfers involving at least $10.71 million in crypto assets. Investigators noted that the campaign has broadened beyond exchanges and large institutions to focus heavily on individual developers, freelancers and other Web3 professionals.
According to the alert, the operation often begins with an enticing "high salary" approach rather than classic phishing emails. Attackers impersonate AI, crypto or NFT companies and contact software engineers via social media, job boards, gig platforms and freelance marketplaces. After an initial exchange, victims are invited to a video interview or asked to complete a coding test.
The compromise typically occurs during the "technical assessment" stage. Victims may be sent a code repository and instructed to run it locally, fix bugs, or troubleshoot supposed video-conferencing issues. While the projects appear to be normal JavaScript, Python or VS Code repositories, they contain embedded malicious code. WaterPlum has been linked to the use of malicious NPM (Node.js package manager) packages and multiple malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
Some samples abuse the .vscode/tasks.json configuration so code executes automatically after a user opens a folder and clicks "trust" in Visual Studio Code. For the target, the steps can look routine: download the repo, open the project and run it as instructed by the "interviewer," while malware installs silently in the background.
Once initial access is gained, the group deploys remote access trojans to retain long-term control and uses information-stealing tools to collect data. The advisory listed key targets, including:
- Browser-saved accounts and passwords
- Clipboard contents, keystroke records and screenshots
- Crypto wallet private keys, recovery phrases and related data
- Local files and shared folders
- Photos of identity documents such as driver's licenses and passports
The data is exfiltrated to attacker-controlled servers. Officials warned that even if a wallet holds no funds at the time, stolen private keys or seed phrases allow attackers to monitor addresses over time and drain funds later.
Investigators also emphasized that the impact can extend well beyond personal wallets. Because developers often have access to corporate repositories, cloud environments and internal systems, compromised credentials and permissions stored on a device can be leveraged to penetrate employers', clients' or partners' networks. That access can facilitate theft of trade secrets, lateral movement within enterprise systems, extortion, or further impersonation.
The notice said stolen identity documents have an additional role in a related scheme: they may be provided to North Korean IT workers who pose as overseas developers to secure jobs and generate foreign-currency income. Authorities said WaterPlum's malware distribution via fake job postings overlaps in people and infrastructure with these North Korean IT worker operations.
The NPA and FBI assessed that WaterPlum members and certain North Korean IT personnel are tied to the 313th Bureau of the Military Industry Department under the Central Committee of the Workers' Party of Korea. To bypass employer checks on identity and work location, the IT workers reportedly coordinate with overseas intermediaries who set up workstations at local residences, supply identity details and receive salaries, while the actual work is performed remotely from North Korea, Russia and other locations. Using local networks and devices in places such as Japan or the United States can make it appear the employee is physically present.
Japanese authorities said this is the first time they have identified such a facility in Japan. The investigation found the participants not only helped disguise identities and obtain employment, but also transferred tens of millions of yen overseas, including through cryptocurrency.
The advisory cautioned that companies and individuals who hire these IT workers, make payments to them, or assist with identity information, bank accounts or remote devices may violate local laws and run afoul of sanctions on North Korea. It also flagged operational and security risks beyond funds flowing to North Korea, citing cases in which a North Korean IT worker extorted an employer over a pay dispute and leaked proprietary source code, and another contractor allegedly sabotaged a website, rendering it inaccessible.
Crypto firms were highlighted as priority targets. In May 2025, a Japanese cryptocurrency exchange received an application for an engineering role from a candidate suspected to be a North Korean IT worker. The applicant accessed the posting via VPN and submitted what authorities described as a fabricated resume. The resume claimed broad mastery of programming languages, blockchain and crypto systems, and cloud services, listing more than 10 skills and experiences under each category. It also cited education at European universities and work history across multiple European and Asian cities over a short period.
During a video interview, the applicant said they were born in Malaysia and lived in Finland, with Malay and Chinese as native languages. Investigators said the person's English level did not match the stated education and experience: they could answer only basic questions and could not explain most of the technical skills on the resume in detail.
The notice also listed interview traits observed across other suspected cases, including refusal to meet in person, requests to be paid in cryptocurrency, frequent glances at another screen, occasional background voices, and repeated video or audio buffering. Authorities said looking off-screen may suggest the candidate is reading answers supplied by someone else, and that multiple people may be collaborating off-camera even when a single person appears on the call.
The agencies warned that discovering an infection and removing malware may not be sufficient. Even if no assets have been moved, untrusted code execution can mean private keys, seed phrases or browser credentials have already been captured but not yet used, and attackers may have installed backdoors for later access.
International guidance cited in the alert recommends never running code from unknown parties on devices that store crypto assets or handle sensitive information. If testing is unavoidable, use an isolated sandbox or virtual machine and review projects for obfuscated or unreadable code, or components that auto-download payloads.
The advisory urged heightened scrutiny for scripts containing commands such as curl, base64, mshta, InvokeWebRequest, or similar tooling used to download, encode or conceal execution, and to avoid running them without fully understanding their purpose.
If antivirus tools flag a device, or if a program from a suspicious recruiter has already been executed, users were advised to immediately disconnect the device from the network. Even if malware is later removed, authorities said victims should assume wallet data is compromised: create a brand-new wallet on a separate secure device, transfer assets, and store the new recovery phrase offline. Because undiscovered backdoors may remain, the safest approach is to back up essential data and fully reinstall or reset the operating system rather than continuing to use the existing environment.