Urgent.News

What's breaking now, across thousands of outlets.

Tech

North Korean hackers behind crypto thefts across 100 countries, including Japan

The North Korean group, called WaterPlum, infected more than 30,000 devices with malware between December last year and July this year.

North Korean hackers behind crypto thefts across 100 countries, including Japan

A North Korean hacking group, known as WaterPlum, orchestrated a cyberattack affecting over 100 countries, including Japan, resulting in the theft of approximately ¥1.7 billion worth of cryptocurrency. The criminal operation, which spanned between December of the previous year and July of this year, involved infecting more than 30,000 devices with malware. This malware was designed to steal login credentials for around 7,000 cryptocurrency accounts.

The National Police Agency (NPA) of Japan, along with seven organizations from four countries, including the U.S. Federal Bureau of Investigation (FBI), released a warning document attributed to the WaterPlum group. This document aimed to deter future cyberattacks by exposing the identities of those responsible.

WaterPlum employed a tactic of posing as corporate headhunters to lure IT professionals into downloading malware disguised as technical assessments. The stolen credentials were then used to transfer cryptocurrency from compromised accounts. Most of the stolen cryptocurrency is believed to have originated from these compromised accounts.

The report also revealed that North Korean IT workers living in North Korea, China, and Russia were earning foreign currency by taking on remote programming jobs under false identities. This illicit activity contributed to the transfer of hundreds of millions of yen to North Korea in recent years. These operations were supported by individuals residing in Japan, who provided the necessary computers, servers, identification documents, and financial accounts.

Japanese authorities successfully dismantled the WaterPlum network through their investigation. The IP addresses used by WaterPlum during the cyberattack were found to match those utilized in the cryptocurrency-earning activities and job applications. Both WaterPlum and some North Korean IT workers are believed to operate under the 313 General Bureau of the Munitions Industry Department, responsible for weapons development and IT strategy under the Central Committee of the Workers Party of Korea.

Written by urgent.news from Japan Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at japantimes.co.jp →

More in Tech

What Mutation Testing Frameworks Do When a Timeout Kills Them

Code: Megapixel99/assay-checks assay audits mutation harnesses: the scripts that deliberately break your code and check that a test notices.

  • Mutation testing frameworks may fail due to timeout signals
  • SIGKILL cannot be caught or handled by frameworks
  • Issue affects mutmut, cosmic-ray, Stryker, and PIT

The Automation Gap Is a Finance Workflow Problem, Not a Spreadsheet Problem

Recent fintech research has put a useful number on an old frustration: UK businesses are still losing several days a month to manual finance administration.

  • UK businesses lose days monthly to manual finance administration.
  • Finance workflow complexity, not spreadsheets, is primary problem.
  • Successful automation focuses on workflow, not just replacing tools.

More from Saturday 19 September →