Decrypt 2026-09-23 12:15

North Korea's Fake Job Interviews Drained $11M From 7, 000 암호화폐 Wallets

North Korea's Fake Job Interviews Drained $11M From 7, 000 암호화폐 Wallets

A North Korean crew that poses as recruiters to compromise developers has taken funds or credentials from more than 7, 000 cryptocurrencywalletsand moved around $10. 71million to Pyongyang, seven agencies across four countriessaidin a joint advisory published on September 18.

The group, which Japan's National Police Agency calls Water Plum and the security industry knows as Contagious Interview, infected at least 30, 000 devices in more than 100 countries between roughly December 2025 and July 2026. Targets were web designers, engineers and specialists in 암호화폐, 블록체인 and Web3 work.

North Korean cyber group “Water Plum” is compromising job seekers’ computer networks, harvesting sensitive data, and stealing 암호화폐 - targeting IT professionals in Japan, U. S. , Europe, and beyond. Read our advisory with@FBIand@NPA_KOHOathttps: //t. co/ugVY5mmo6ypic. twitter. com/Q74qeXWQoP

— DoD Cyber Crime Center (DC3) (@DC3Forensics)September 18, 2026

It is signed by Japan's National Police Agency and National Cybersecurity Office, the FBI and the U. S. Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's BND foreign intelligence service and BfV domestic security agency.

The NPA and the FBI assess that both Water Plum and some of North Korea's remote IT workers report to the 313 General Bureau of the Munitions Industry Department, which sits under the Workers' Party central committee. The two operations also used the same IP addresses to reach laptop farms, use crowdsourcing services and apply for jobs, which the agencies treat as evidence the two are one operation.

Actors impersonate AI, 암호화폐 or NFT companies, approach developers through social media, job boards and freelance marketplaces, then set a technical interview or coding task. Candidates are told to download files from developer platforms, either to finish the assignment or to fix an apparent fault in the video call. The advisory names five malware families carried in those packages, among them Beaver Tail, Invisible Ferret and Stoat Waffle, the last of which hides in 블록체인-themed repositories.

The advisory also logs what investigators observed of the crew itself. Members used AI face-swapping software in interviews before cutting video and asking the candidate to do the same, blaming the connection. They practised Japanese pronunciation with text-to-speech tools, worked consistently on free machine-translation and AI tiers, and on holidays celebrated in North Korea played games and watched soccer videos instead of running their usual operations.

Japanese authorities also identified and dismantled a laptop farm run by a domestic enabler, the first such case in the country, finding evidence that several hundred million yen in 암호화폐 had moved abroad. A laptop farm is usually an enabler's home, where work computers are run remotely by IT workers in North Korea, China or Russia.

A Japanese 암호화폐 거래소 turned away an applicant in May 2025 whose résumé claimed implausibly broad skills and whose English did not match the record. Other tells include refusing to meet in person, asking to be paid in 암호화폐, and glancing repeatedly at a second screen.

The theft sits inside a far larger campaign. Certi Kattributed60% of all 암호화폐 theft losses in 2025, some $2. 06billion, to North Korea-linked groups, and April's$285million Drift Protocol hackfollowed six months of attackersposingas a quantitative 거래 firm.

출처: Decrypt