North Korean Hackers Compromise Thousands of Devices Stealing Crypto Wallet Data
A North Korean hacking group called WaterPlum has compromised over 30,000 devices across more than 100 countries and regions, stealing information from more than 7,000 cryptocurrency wallets. The group, linked to Bureau 313 of the Workers' Party of Korea's Munitions Industry Department, posed as crypto, AI, and NFT companies to target developers with fake job opportunities.
The attackers created malicious files disguised as interview tasks and coding tests, which were downloaded by victims through collaborative development platforms and code repositories. This allowed WaterPlum to establish backdoors and use remote access tools to retain access and move through affected systems.
The stolen information included browser credentials, keystrokes, screenshots, clipboard data, private keys, and seed phrases for cryptocurrency wallets, as well as identity documents such as passports and driver's licenses stored on affected computers or shared folders.