Japanese and U.S. authorities, including the FBI, confirmed the group targets web designers and blockchain engineers by posing as legitimate AI or NFT companies. Attackers utilize malicious coding tests and interview assignments to deploy a suite of information-stealing software, such as BeaverTail and InvisibleFerret. These tools grant the group persistent access, allowing them to harvest browser credentials, identity documents, and private keys from infected machines.
Beyond direct cyberattacks, the investigation uncovered an extensive network of “laptop farms” used to facilitate illicit employment. By using stolen identities and remote access tools, North Korean IT workers secure jobs at Western and Japanese firms, funneling their earnings—which have reached at least 1.7 billion yen—back to state-controlled coffers. In one instance, a suspected operative attempted to infiltrate the exchange bitFlyer in 2025, providing fake credentials and insisting on cryptocurrency payments before being flagged by security protocols.
Authorities warn that the infrastructure used for these recruitment schemes is technically linked to the WaterPlum hacking operations. Companies are now advised to rigorously verify candidate locations and scrutinize applicants who avoid video verification or demand non-traditional payment methods. This integrated approach to cybercrime demonstrates a shift toward using the tech sector’s own hiring processes as a vector for both data theft and long-term financial extraction.

Comments (0)
No comments yet. Be the first!