Japan, U.S., Australia and Germany issue joint report on North Korea-linked hacking group WaterPlum
AI مارکیٹ کا خلاصہ
A multi-agency Japan-US-Australia-Germany report attributes WaterPlum's long-running "fake interview" malware campaign to North Korea-linked operators, citing theft of thousands of crypto wallet credentials and documented laundering flows. The disclosure highlights a scalable intrusion path from individual developer machines into corporate networks and crypto exchanges, raising near-term operational and compliance risk for the crypto sector and potentially tightening security scrutiny across hiring and outsourcing pipelines.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+2.96%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
On Sept. 18, Japan's National Police Agency (NPA) and National Cyber Coordination Office, together with the U.S. FBI and Department of Defense Cyber Crime Center, Australia's Signals Intelligence and Cyber Security Centre, and Germany's Federal Intelligence Service and Federal Office for the Protection of the Constitution, released a joint report on a North Korea-linked hacking cluster known as WaterPlum, also referred to as "Contagious Interview" ("Fake Interview").
The campaign has been tracked for years by multiple international security firms and is often associated with North Korea's Lazarus Group. The NPA said this is the first time Japanese police, under official auspices and in cooperation with multiple overseas agencies, have disclosed specific domestic cases and related seized evidence.
Report link: Core data
How the WaterPlum attacks work
1) Employer impersonation and outreach
WaterPlum typically approaches IT professionals through social media, job boards, gig platforms and freelance marketplaces, with a focus on web developers and engineers in the cryptocurrency and blockchain sector. The actors may pose as AI startups, crypto asset firms, NFT projects or recruiters.
2) "Technical interview" bait
After initiating contact, victims are invited to a "technical interview" or given a programming test. They are instructed to download a "project file" from a code repository such as GitHub, framed as tasks like "fix a bug in this video conferencing tool" or "complete the test using this template." The downloaded material is often malware.
3) Malware execution (including VS Code traps)
The report names several malware families tied to the activity: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.
StoatWaffle is highlighted for masquerading as a blockchain-related repository and using Visual Studio Code configuration to trigger execution via a .vscode/tasks.json file. Authorities warn that simply opening a project folder and selecting "Trust" can be enough to run code in the background without the user explicitly launching it.
The police advise opening unfamiliar VS Code projects in "Restricted Mode" and selecting "No" when asked "Do you trust the author of this folder?" They also recommend avoiding placing unknown projects inside previously trusted folders and not disabling Workspace Trust for convenience.
4) Credential theft and corporate intrusion
The malware is often embedded in NPM packages disguised as legitimate libraries. Once executed, it can install backdoors, connect to remote servers and collect sensitive data including browser-stored passwords, clipboard contents, keystrokes, screenshots, crypto wallet private keys and seed phrases, and images of identity documents such as driver's licenses and passports.
Authorities say the objective is not limited to selling credentials. Stolen logins can be used to access victims' employer networks for deeper compromise, including intellectual property theft and lateral movement. Identity documents may also support North Korean IT workers impersonating others to access overseas job markets.
Scale and proceeds
Law enforcement data covering December 2025 to July 2026 indicates that at least 30,000 computers were compromised across more than 100 countries and regions, over 7,000 cryptocurrency wallet details were stolen, and roughly 1.7 billion Japanese yen (about $10.71 million) flowed into wallets controlled by WaterPlum.
Japan's first "laptop farm" raid
A central takeaway of the report is the first domestic seizure and dismantling of a "laptop farm" in Japan.
In this setup, North Korean IT workers located outside Japan persuade or pay a Japan-based intermediary to host computers at home. The devices are remotely controlled from abroad, making it appear to employers that work is being performed locally in Japan even if the operator is in North Korea, China or Russia.
The Japan-based accomplice, described in the report as a "supporter," provided physical space for the machines, internet access and, in some cases, identity documents used for impersonation in job applications. In certain arrangements, work was performed entirely by the North Korean workers under the supporter's identity; in others, payments were routed into the supporter's bank account and then moved onward. VPS servers rented under the supporter's name were also used to further obscure operations.
Police concluded that, through this method, North Korean IT workers moved cryptoassets worth hundreds of millions of yen overseas. The report states the proceeds were used for purposes including weapons development. It also warns that hiring and paying North Korean IT workers may breach domestic laws and North Korea-related sanctions.
Case study: bitFlyer job application
The report includes a detailed case involving Japanese cryptocurrency exchange bitFlyer.
In May 2025, bitFlyer received an engineering application later assessed as likely linked to North Korean IT workers. The candidate applied directly via the company's website using a Gmail address and accessed the job portal through a VPN. The report flags NETNUT Proxy, Astrill VPN and High Speed Rabbit Proxy.
The resume listed unusually broad capabilities, including proficiency in more than a dozen programming languages, expertise in blockchain and cloud services, a European university degree and work experience across multiple countries.
bitFlyer proceeded cautiously and held a video interview. The candidate appeared Asian but claimed Malaysian heritage and said they had lived in Finland for years, listing Malay and Chinese as native languages. The interview was conducted in English, but the candidate's fluency did not match the profile implied by their education and experience. They could address basic questions but became vague when asked to go deeper.
Additional red flags cited include reluctance or delays around relocating to Japan (e.g., "let's see in six months"), insistence on being paid in cryptocurrency, frequent glances at another screen suggesting they were reading answers, occasional background voices, and recurring video lag or frame drops.
bitFlyer ultimately did not hire the applicant and is acknowledged in the report's credits.
Linking WaterPlum to North Korean IT worker operations
The NPA and FBI state that WaterPlum's cyberattacks and certain foreign currency-earning activities by North Korean IT workers are directed by the 313 Bureau of the Military Industry Department of the Workers' Party of Korea Central Committee.
A key basis cited is IP overlap: IP addresses used by WaterPlum operators, by North Korean IT workers connecting to laptop farms and crowdsourcing platforms, and by the bitFlyer applicant when logging into the job portal were found to match.
The report also describes operational habits, including the use of an AI face-swapping tool called "Magicam" to pass video interviews, typically for only a few minutes before citing "poor network connection" and turning off cameras. On certain North Korean commemorative days, members were reportedly permitted to play games (mainly simulation management titles), and some were observed watching football videos. They used text-to-speech tools such as "NaturalReader" to practice Japanese pronunciation and relied heavily on free tiers of translation and AI tools.
Defensive guidance
For individual IT professionals, especially freelancers:
- Avoid running code supplied by unknown parties on machines used for work or cryptoasset management; if testing is unavoidable, use a virtual machine.
- Treat scripts invoking curl, base64, mshta or InvokeWebRequest as high risk until you understand exactly what they do.
- If antivirus triggers an alert, disconnect from the network first; deleting malware does not rule out prior data theft.
- Move wallet assets to a new wallet promptly and record the mnemonic phrase by hand rather than storing it on a computer.
- If feasible, reinstalling the operating system is a safer remediation option.
For companies hiring or outsourcing:
- Be cautious when a niche role suddenly draws a large volume of resumes in a short period.
- When candidates claim unusually broad skills, use targeted follow-up questions to confirm genuine understanding rather than rehearsed answers.
- Requests for crypto-only payment, refusal to appear in person, or payment instructions to accounts under other people's names warrant heightened scrutiny.
- Light conversation about local weather or daily life can sometimes surface inconsistencies that technical questioning misses.
Bottom line
Authorities frame the WaterPlum findings as more than another North Korea-linked malware disclosure. The report outlines a converging playbook: job-related lures compromise personal devices, stolen access is leveraged into corporate networks, and monetization occurs through credentials and cryptocurrency theft, while separate identity fraud and laptop-farm infrastructure enable infiltration of overseas IT labor markets.
The report closes by warning that tactics will keep evolving and grow more complex, urging both individuals and organizations to track alerts from domestic and international agencies and security vendors.