EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

朝鲜网络钓鱼团伙攻陷3万台设备,窃取1070万美元加密货币

2026-09-21 12:10:17
Bookmark

朝鲜关联黑客组织“WaterPlum”伪装招聘窃取逾1070万美元

据日本、德国、澳大利亚和美国当局联合发布的网络威胁预警,与朝鲜有关联的黑客组织“WaterPlum”(也被追踪为“Contagious Interview”)通过冒充合法的加密货币和人工智能公司进行招聘,诱骗求职者安装恶意软件,目前已至少窃取了1070万美元。该行动针对多个国家的软件开发人员和IT专业人士,将虚假招聘流程与授予攻击者远程访问受害者系统权限的恶意文件相结合,从而实现加密货币及其他敏感信息的盗窃。

关键要点

  • 身份伪装: WaterPlum利用虚假招聘人员身份和招聘服务,冒充真实的加密货币、区块链、人工智能和Web3公司。
  • 诱导下载: 受害者通常被指示下载并运行伪装成编码任务或视频会议故障排除步骤的恶意软件。
  • 战略背景: authorities将该组织与朝鲜更广泛的策略联系起来,即在外国组织内部安置IT工作人员。
  • 影响范围: 据报道,在2025年12月至2026年7月期间,超过100个国家至少有3万台设备感染,超过7000个加密货币钱包被盗。
  • 后续风险:除财务盗窃外,被盗的文件和个人数据可能被用于身份冒用、勒索或进一步渗透雇主系统。

以虚假招聘为切入点

在预警中,相关当局描述了WaterPlum对从事加密货币、区块链和Web3相关技术的网页设计师、工程师和专家的 targeting。报告显示,攻击者通过社交媒体、在线就业平台、零工服务以及自由职业市场联系候选人。一旦候选人产生互动,假冒者便指示受害者下载并执行恶意文件,将其包装为编码作业或解决视频会议错误的排查步骤。

虽然招聘诈骗并不新鲜,但此次行动专注于技术角色和区块链特定专业知识,增加了受害者被“工作任务”叙事说服的可能性——尤其是当恶意文件被伪装成开发交付物时。

从恶意软件到钱包盗窃和数据泄露

预警指出,该计划超出了欺骗范畴,最终导致系统被攻破。在获得受害者计算机的后门访问权限后,WaterPlum操作员 reportedly 使用远程访问工具和信息窃取恶意软件来提取敏感数据和加密货币。

攻击者还开辟了进一步渗透的路径:成功的感染可能允许WaterPlum compromised 雇佣这些开发人员的组织,特别是如果受害者被授予访问内部系统、源代码或相关账户的权限。

当局估计,WaterPlum在超过100个国家感染了至少3万台设备。在2025年12月至2026年7月期间,预警指出有超过7000个加密货币钱包的资金或凭证被提取。对于用户和雇主而言,关键风险在于凭证或钱包的泄露可能不仅限于单个终端。如果登录信息、签名密钥或操作细节被收集,攻击者有可能从单纯的盗窃转向持续访问或进一步的欺诈行为。

为何威胁超出加密货币盗窃范畴

联合预警强调,危害可能比被盗的加密货币更为广泛。它警告称,从受害者处获取的身份文件可能使朝鲜IT工作人员能够冒充这些个人并牟取利益,而其他收集的信息可能被用于勒索。

预警还将WaterPlum的活动与朝鲜长期嵌入IT工作人员进入外国组织的努力联系起来。据报告,日本和美国当局评估认为,WaterPlum的行为者以及一些朝鲜IT工作人员是在朝鲜军需工业部的领导下运作的。

在此背景下,以招聘为驱动的恶意软件活动具有双重功能:短期内窃取资金,长期内支持渗透或欺诈——特别是当受害者的身份被泄露时。

现实案例凸显操作手法

The alert described a case in which a suspected North Korean IT staff used forged resumes to apply for engineering positions on the Japanese cryptocurrency exchange. Authorities said discrepancies emerged during the interview process, including candidates 'inability to explain in detail the skills listed on their resumes, leading the exchange to reject applicants after that.

Recently, previous reports documented an incident involving Consensys in which the company unwittingly hired a developer with ties to North Korea as a consultant. The report pointed out that Consensys terminated access after discovering the threat. The investigation found that no assets or data were stolen, no malicious code was deployed, and no impact on user security.

Together, these cases reveal a common pattern: Recruitment-related penetration attempts may be discovered before they cause harm, but they still create enough risk to require intensified screening, especially for those roles associated with cryptocurrency operations and sensitive technology work.

Part of a broader North Korean fundraising and infiltration script

Operation WaterPlum is seen as another example of North Korea's continued use of cryptocurrency-related theft to raise funds, despite years of warnings and enforcement efforts. Previously, the FBI blamed North Korea for the $1.5 billion theft of Bybit reported in February 2025. At the same time, according to the same report, U.S. authorities have been warning about North Korea's hidden IT workers since 2018.

WaterPlum warnings are particularly important because they combine financial crime and human resource penetration. This job-linked malware delivery demonstrated how attackers tried to take advantage of legitimate recruitment processes in an industry where technical trust and remote work are prevalent.

Looking to the future, the most important open issue facing organizations is how to quickly and consistently detect recruitment-related vulnerabilities-especially when malware is introduced through "normal" workflows such as coding jobs and meeting fixes. Readers should pay attention to subsequent warnings about mitigation steps, and employers should view suspicious recruitment routes as cybersecurity incident risks, not just fraud issues.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP