North Korean Hackers Steal Millions with Fake Job Postings
The North Korean hacker group WaterPlum, also known as Contagious Interview, has been using fake job postings to steal cryptocurrency assets from software developers and IT professionals worldwide. The group poses as employers offering lucrative job opportunities in AI, cryptocurrency, and NFT companies, and asks candidates to complete coding tests or troubleshoot an issue for an online video conferencing platform.
The malware package contains multiple families of malware, including BeaverTail, InvisibleFerret, OtterCookie, and a novel payload called StoatWaffle. Once executed, the malware copies passwords, performs keylogging, takes screenshots, harvests crypto wallet seed phrases, and steals passport photos. The group has compromised at least 30,000 devices across more than 100 countries, stolen funds and credentials from over 7,000 crypto wallets, and amassed $10.7 million in proceeds.
Japanese police have released a nine-page advisory jointly signed by seven institutions from Japan, the US, Australia, and Germany. The group is an affiliate of the 313 Bureau under the Department of Machine-Building Industry of North Korea. Ido Sofer, founder of key management firm Sodot, stated that these attackers operate as highly organized entities with KPIs, set objectives, clock into offices, and execute comprehensive operational strategies.