उत्तर कोरियाई हैकर्स ने घोटाले में 7,000 क्रिप्टो वॉलेट को बनाया निशाना

मुख्य बातें:

  • In today’s क्रिप्टो स्कैम news, North Korea-linked WaterPlum infected more than 30,000 devices.
  • The campaign stole data from more than 7,000 crypto wallets.
  • Controlled wallets received at least $10.71 million in crypto.

Between December 2025 and July 2026, North Korea-affiliated hackers infected over 30,000 devices across more than 100 countries and regions. According to Japan’s National Police Agency, the group known as WaterPlum compromised information belonging to upwards of 7,000 क्रिप्टो वॉलेट.

Investigators also discovered approximately $10.71 million transferred into wallets managed by the operation. This malicious push merged digital asset thefts with deceptive recruitment schemes aimed at technology professionals.

The global probe brought together Japan’s National Police Agency, National Cyber Office, FBI, DC3, ASD, ACSC, BND, and BfV. Officials additionally investigated North Korean IT personnel involved in international employment and foreign currency acquisition.

Crypto Scam Report | Source: npa.go
Crypto Scam Report | Source: npa.go

Crypto Hacks Use Fake Recruitment Campaigns

WaterPlum targeted software engineers, developers, and Web3 specialists through freelance platforms, job boards, and social media networks. The actors posed as legitimate recruitment, artificial intelligence, crypto, and NFT firms to pitch job openings.

During the assignment stages, WaterPlum directed job applicants to download software packages from code repositories and collaborative developer platforms. In some instances, attackers disguised these files as utilities meant to resolve video-conferencing bugs.

Concurrently, WaterPlum deployed harmful NPM libraries including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. These specific malware variants enabled remote system access, credential harvesting, and data collection.

The harvested details encompassed browser logins, clipboard contents, keystrokes, screenshots, निजी कुंजी, and wallet recovery seed phrases. The perpetrators additionally hunted for personal identification files like passports and driver’s licenses.

Crypto Scam Connect With Laptop Farms

Japanese law enforcement uncovered the nation’s initial domestic laptop farm linked directly to North Korean IT laborers. Police seized hardware set up inside the home of a local facilitator.

The overseas workers connected to these machines remotely while applying for outsourced tech positions, utilizing virtual private servers to hide their physical whereabouts.

Certain workers utilized stolen identity papers belonging to third parties to secure contracts, while others routed their earnings through bank accounts controlled by local accomplices.

Investigators uncovered that North Korean technology workers funneled cryptocurrency and funds amounting to hundreds of millions of yen abroad. Operatives functioned out of regions including North Korea, China, and Russia.

Specific WaterPlum participants even fulfilled web development and design commissions for businesses located in the United States and Japan. Authorities linked portions of this infrastructure to Bureau 313.

Furthermore, select individuals लीवरयुक्त Magicam face-swapping programs during video interviews, alongside NaturalReader to polish their Japanese phrasing and standard generative AI utilities.

Hackers Target Japanese Crypto Exchange Jobs

The findings outlined a job submission from May 2025 sent to Japanese digital asset एक्सचेंज bitFlyer, suspected to originate from a North Korean IT operative.

The candidate used an alias identity, applied straight through bitFlyer’s hiring portal, and routed the connection using Gmail alongside multiple VPN services.

The attached resume showcased extensive cloud computing, crypto, blockchain, and coding proficiencies, alongside purported European academic credentials and international work history.

Yet, bitFlyer flagged multiple discrepancies throughout the virtual interview process. The candidate claimed citizenship in Malaysia while currently living in Finland.

The applicant also pushed back against relocating to Japan and requested compensation entirely in crypto tokens. Panelists noticed the individual frequently glancing at a separate monitor alongside background noises.

The video feed experienced periodic disruptions throughout the meeting. BitFlyer ultimately rejected the application and पुष्टि no security breaches or losses occurred.

The FBI and National Police Agency determined that Bureau 313 drives both operational areas. Bureau 313 functions underneath the Munitions Industry Department of the Workers’ Party of Korea.

NTT Security Japan and bitFlyer provided सपोर्ट for the public warning. Japanese law enforcement officials also incorporated data sourced from private industry partners during their inquiries.

अक्सर पूछे जाने वाले प्रश्न

  • What is WaterPlum?
    WaterPlum is a North Korea-linked hacker group that targets tech workers with fake job offers to steal cryptocurrency and sensitive data.
  • How many crypto wallets were compromised?
    The campaign successfully stole information from more than 7,000 crypto wallets across over 100 countries and regions.
  • How much money did the hackers steal?
    Authorities discovered at least $10.71 million transferred directly into crypto wallets controlled by the hacker network.
  • What malware did the hackers use?
    The group distributed malicious NPM packages containing malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
यह निवेश सलाह नहीं है यहाँ प्रकाशित विश्लेषण केवल जानकारी के लिए है। डिजिटल एसेट अस्थिर होते हैं और आप अपनी स्थिति का पूरा मूल्य खो सकते हैं। कोई भी कदम उठाने से पहले अपनी खुद की रिसर्च करें।

ग्लोरी कबुरु

प्रतिक्रिया दें

आपका ईमेल पता प्रकाशित नहीं किया जाएगा। आवश्यक फ़ील्ड चिह्नित हैं *