Overview
- The joint alert issued on Friday says WaterPlum infected more than 30,000 devices across over 100 countries and exfiltrated records from more than 7,000 cryptocurrency wallets that moved roughly $10–11 million to actors tied to North Korea.
- Agencies in Japan, the U.S., Australia and Germany assessed that WaterPlum and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, a unit of North Korea’s ruling party.
- Investigators found attackers lured software developers with fake AI, crypto and NFT job postings and coding-test files that loaded malware (named BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle) which stole browser credentials, keystrokes, screenshots, private keys, seed phrases and identity documents.
- Japanese police dismantled a domestic laptop farm that let North Korean workers remotely control machines and route payments through local facilitators, and authorities have pursued related prosecutions and crypto asset forfeitures in multiple countries.
- Officials advise employers to verify applicants’ claimed locations and skills, to watch for the disclosed malware and infrastructure indicators, and to scrutinize requests for cryptocurrency payment because those checks are central to disrupting this revenue-generation scheme.