Coding Interview = Stolen Wallet? North Korean Hacker Group WaterPlum’s Hiring Scam Exposed | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


North Korean WaterPlum hackers stole $10.7 million in cryptocurrency assets using fake job postings.

Written by: Boaz Sobrado

Translated by: Luffy, Foresight News

Hackers from this country once stole $1.5 billion from the Bybit exchange in a single day, while over the past nine months they have targeted comparatively smaller prizes: sending fake job offers to programmers. Last Friday, the FBI and the Japan National Police Agency released relevant case data, revealing that hackers had compromised at least 30,000 devices across more than 100 countries, stolen funds and credentials from over 7,000 crypto wallets, and amassed $10.7 million in proceeds, which ultimately flowed to Pyongyang.

This nine-page advisory was jointly signed by seven institutions from Japan, the US, Australia, and Germany. Japanese police refer to this disclosure model as “public attribution,” directly naming the state actors behind the attacks to serve as a deterrent. The hacktivist group operates under the codename WaterPlum, though the cybersecurity industry is better acquainted with its alias “Contagious Interview.” These agencies categorize it as an affiliate of the 313 Bureau under the Department of Machine-Building Industry of North Korea, a department also alleged to direct some of the country’s fake remote IT workers.

“Troubleshooting an Issue for an Online Video Conferencing Platform”

This attack vector essentially functions as a fake recruitment pipeline. According to the advisory, members of the WaterPlum group pose as employers, using lucrative job opportunities as bait to target software developers and IT professionals worldwide, often spoofing fictitious AI, cryptocurrency, and NFT companies.

Candidates are asked to complete coding tests or “troubleshoot an issue for an online video conferencing platform,” with the so-called fix being a code archive. The package contains multiple malware families: BeaverTail, InvisibleFerret, OtterCookie, and a novel payload called StoatWaffle. It hides within blockchain-themed project folders; the moment a developer opens the folder in VS Code and clicks the “Trust” button, the malware executes automatically.

Once executed, the malware copies passwords, performs keylogging, takes screenshots, harvests crypto wallet seed phrases, and steals any available passport photos. When asked on the On The Margin podcast whether any application can be safer than the mobile operating system it runs on, Yoon Auh, founder of security firm Boltz Technologies and former VP of IT at Goldman Sachs, replied, “If someone is dead set on targeting you, it’s nearly impossible to avoid them. Unless you replace all your devices, there’s virtually no defense.”

“They’re Watching Football Matches”

In a highly unusual disclosure, the advisory reveals details about the attacker on the other end of the call. Interviewers use AI face-swap software, turn off their cameras after a few minutes, and make excuses about network issues to get candidates to do the same. They also utilize text-to-speech tools to practice Japanese pronunciation. Japanese police investigation found that during North Korean national holidays, “attackers play video games and watch football matches, suspending malicious activities.”

This group of hackers also proactively submits resumes. In May 2025, a Japanese crypto exchange received an engineering job application. The applicant claimed to be born in Malaysia, based in Finland, and a graduate of a European university, but their English proficiency drastically mismatched the education and work background listed on the resume, resulting in the application being rejected.

Police also listed other identifying red flags: applicants requesting salary payments in cryptocurrency, frequently glancing at another monitor during the interview (as if reading cue cards), and background noise of other people speaking.

Japanese police also dismantled the first known “laptop farm” in Japan—a network of computers kept running 24/7 by local accomplices for overseas hackers to assume identities and conduct remote operations. In a private residence, local accomplices maintained multiple work computers continuously powered on, enabling North Korean hackers abroad to assume false identities and take on remote freelance projects. According to Jiji Press, these accomplices lent out their ID documents and bank accounts, allowing hundreds of millions of yen in illicit funds to flow out of Japan through this hub. The advisory indicates that WaterPlum hackers have used the same IP addresses as this cohort of fake IT workers.

“They Have Their Own KPIs Too”

To Pyongyang, $10 million is hardly a staggering sum. Data from TRM Labs shows that in the first half of 2026, the total amount stolen globally by crypto hackers reached $972 million, of which $643 million is linked to North Korea, with the vast majority stemming from two April attacks on Drift and KelpDAO. TRM Labs further noted that this figure represents “only a portion of North Korea’s crypto revenue,” as it excludes gains from phishing attacks, social engineering campaigns, and “covert operations disguised as IT personnel.” The advisory released last Friday accounts for this gray-market income, averaging approximately $1,500 stolen per deceived user’s wallet, victims having believed they were attending job interviews.

Ido Sofer, founder of key management firm Sodot, stated on the On The Margin podcast that these attackers operate as highly organized entities. “They have KPIs, set objectives, clock into offices, and execute comprehensive operational strategies. Especially for state-sponsored actors like North Korea, they invest massive resources to achieve their goals regardless of the cost. Once a state-level entity targets an individual, it is nearly impossible to defend against them.”

Dmitry Machikhin of analysis firm BitOK, who previously tracked the stolen Bybit funds, noted in an interview, “We have already identified certain addresses and wallets used by the Lazarus Group to stash illicit funds. But that’s the extent of what we can do; we lack the authority to make any arrests.”

“Don’t Let a Compromised Single Device Lead to a Full System Breach”

The official guidance for all victims who ran code packages sent by recruiters is straightforward: assume your wallet information has already been compromised. “Create a new wallet on a separate, pristine device, transfer all assets to it, back up the new seed phrase offline, and then completely wipe the infected old device.”

Past discussions on crypto security have largely centered on exchange risks, whereas the risk source in this attack traces back to a personal laptop.

Auh’s stance is that preparedness for potential breaches should be prioritized in advance, rather than relying on the hope of building impenetrable defensive walls. “We know no system can block every attack vector. If one device has already been breached, do not let that compromise spread, triggering a total loss across your entire infrastructure.”



Click Here For The Original Source.

——————————————————–

..........

.

.