ZeroHour
CyberScooppublished ()ingested Tim Starks
Part of a story covered by 3 sources: “North Korea's WaterPlum fake-recruiter campaign infects 30,000+ devices across 100+ countries, stealing $10.5M–$11M from crypto wallets; nations act on DPRK IT workers” — merged summary and timeline →

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

highThreat actor exploited in the wildimportance 78
AI summary · glm-5.3-flash

US, Japanese, German, and Australian agencies warn North Korea's WaterPlum gang poses as recruiters, infecting 30,000+ devices and stealing about $11 million in crypto.

The FBI, DoD Cyber Crime Center, and agencies from Japan, Germany, and Australia attributed WaterPlum (Contagious Interview) to the 313 General Bureau of North Korea's Munitions Industry Department under the Workers' Party of Korea. The group poses as recruiters from fake AI, cryptocurrency, and NFT companies to target software developers and IT professionals, infecting more than 30,000 devices in over 100 countries. Operators have transferred roughly $11 million in cryptocurrency from more than 7,000 wallets to North Korea. Japanese authorities dismantled a laptop farm for the first time, and WaterPlum actors substantially overlap with North Korean IT worker schemes, sharing IP addresses and infrastructure.

  • WaterPlum attributed to the 313 General Bureau of the Workers' Party of Korea
  • Poses as AI, crypto, and NFT recruiters to infect 30,000+ devices in 100+ countries
  • Nearly $11 million in cryptocurrency transferred from over 7,000 wallets
  • Japan dismantled a laptop farm; FBI prosecuting US-based facilitators
  • Substantial overlap with North Korean IT worker operations and laptop farms
Full article636 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide.

Flag of the Democratic People's Republic of Korea (Manuel Augusto Moreno)

North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.

The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”

Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.

They’ve used the stolen information to fuel other operations, and the overlap between WaterPlum and North Korean IT workers is substantial, the agencies said.

“WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange,” they wrote.

Collectively, WaterPlum has infected more than 30,000 devices in more than 100 countries, targeting IT professionals in Japan, the United States, Europe and other nations. Its operations have transferred the equivalent of nearly $11 million of cryptocurrency from over 7,000 crypto wallets to North Korea, according to the alert.

The law enforcement agencies said they have had some success tackling the group, but are seeking further cooperation and released details in the alert about WaterPlum’s tactics, techniques and procedures.

“For the first time in Japan, authorities successfully identified, investigated, and dismantled a ‘laptop farm’ operated by an enabler in Japan,” the alert reads. “Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan. The FBI continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers.”

The warning comes as the Multilateral Sanctions Monitoring Team, an international panel overseeing UN sanctions against North Korea, released a report exposing thousands of North Korean nationals employed in industries around the world.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/