Japanese Authorities Warn of North Korean Hacking Group WaterPlum
Japanese authorities have issued a warning about a North Korean hacking group called WaterPlum. The group, linked to the 313 Bureau of North Korea's Department of Military Industry, has been associated with hacking approximately 30,000 devices and compromising over 7,000 cryptocurrency wallets.
According to the investigation, the group transferred around $10.71 million in stolen digital assets to North Korea. Hackers from WaterPlum pose as employers and recruiters, including on behalf of companies in the AI and cryptocurrency sectors, and send victims malicious files allegedly to test skills or fix issues during interviews.
The group uses trojans and info-stealers to take control of devices, then steals browser data, private keys, seed phrases, and identity documents. Authorities have identified several malware variants used by WaterPlum, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
The warning also mentions signs of suspicious job seekers, such as refusal to meet in person, requests for salary payments in cryptocurrency, and video and audio glitches during interviews. Japanese authorities have identified and shut down a 'laptop farm' operated by a local intermediary for the first time, which transferred several hundred million yen abroad in cryptocurrency.