▲ National Police Agency of Japan
Japanese police announced, in coordination with multinational investigative agencies including those in the United States, that they have confirmed North Korean cyber groups disguised as headhunters to steal massive amounts of cryptoassets worldwide.
The National Police Agency of Japan and the National Cyber Directorate (NCO) announced on the 18th that, alongside the U.S. Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center (DC3), and investigative agencies in Australia and Germany, they have identified the attack methods of "WaterPlum," a cyber group backed by North Korea.
According to the Japanese National Police Agency, WaterPlum posed as hiring managers for artificial intelligence (AI) companies, cryptoasset firms, and non-fungible token (NFT) businesses, approaching software developers and IT engineers with attractive scout offers.
They then presented programming tasks under the guise of "testing technical skills" or conducted online interviews, tricking victims into downloading and executing files or programs containing malicious code to infect their computers with malware. Afterward, they seized cryptoasset wallets and forced the victims to transfer funds to crypto wallets owned by the group.
The Japanese National Police Agency explained that through this method, over 30,000 devices were infected from last December to July of this year, allowing WaterPlum to steal a total of 7,000 cases of cryptoassets amounting to 1.7 billion yen (approximately 14.5 billion won) across around 100 countries and regions, including Japan.
The Japanese National Police Agency believes that WaterPlum operates under the direction of the Munitions Industry Department's 313th Bureau of the Central Committee of the Workers' Party of Korea.
In addition, the National Police Agency revealed that it has identified North Korean IT workers operating under the direction of the Workers' Party of Korea to earn foreign currency by remotely controlling the computers of "domestic enablers" within Japan.
The agency explained that North Korean IT workers concealed their true identities while posing as enablers, securing IT tasks and web system design and development work from Japanese companies to receive compensation.
The Japanese National Police Agency estimates that the funds funneled back to North Korea through these activities amount to several hundred million yen (billions of won).
The National Police Agency published WaterPlum's specific methods and countermeasures on its website, urging related organizations and businesses to exercise caution.
(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News
Video News
Video News