๐Ÿ“… Wednesday, 23 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Hacker Korea Utara Kuras $10,7 Juta dari 7.000 Dompet Kripto - Modusnya Lewat Wawancara Kerja Palsu

North Korean Hackers Drain $10.7M From 7,000 Crypto Wallets via Fake Job Interviews

The WaterPlum hacking group drained $10.71 million from more than 7,000 crypto wallets between December 2025 and July 2026. Also known across the cybersecurity industry as Contagious Interview, the North Korean threat group targeted specific professionals, including web designers, engineers, and specialists working in the crypto, blockchain, and Web3 ecosystems.

The scale of the attack prompted seven intelligence and cybersecurity agencies across four nations to release a joint advisory on September 18, 2026. Signatories to the advisory document include the FBI and DoD Cyber Crime Center (DC3) from the United States, Japan’s NPA and National Cybersecurity Office, the Australian Signals Directorate (ASD) from Australia, and Germany’s BND and BfV. The joint report revealed that the hacking group infected at least 30,000 devices across more than 100 countries in just seven months.

How the Job Scam Trap Works

The threat actors carried out their operations by posing as recruiters. They actively monitored social media, professional job boards, and freelance platforms to identify candidates matching their targeted technical profiles. Once victims responded to the fake job offers, a convincing interview process began.

During the recruitment process, candidates were instructed to download specific files from developer platforms. The perpetrators used various pretexts, ranging from completing technical assessments required to pass the interview to simple excuses like fixing application glitches during a video call. The downloaded files contained malicious code that granted hackers direct access to victims’ hardware to siphon assets from their crypto wallets.

IP Address Trails and Centralized Command

An investigation by the NPA and FBI uncovered a state-backed command structure behind WaterPlum’s activities. The hacking group was found to share reporting lines with North Korea’s remote IT worker program. Both reportedly answer to the same entity, General Bureau 313 of the Munitions Industry Department, a division under the Workers’ Party central committee.

The connection between the two divisions was evidenced by digital infrastructure trails. Authorities discovered that the Contagious Interview theft operation and North Korea’s remote worker network routinely shared IP addresses. These identical IP addresses were detected when actors accessed remote device networks or laptop farms, as well as when registering accounts on various job boards. This access pattern led authorities across the four nations to conclude that the crypto recruitment scams and remote worker deployments are part of a single integrated operation.

Reported by Decrypt.

Previously: North Korean Hackers Drain $10.7M in Crypto via Fake Job Offers - Beware of This Coding Test Scheme


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share