{
  "version": 1,
  "event_id": "evt_0698c7a5520034f1",
  "url": "https://xiyu.news/events/evt_0698c7a5520034f1/",
  "json": "https://xiyu.news/api/events/evt_0698c7a5520034f1.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "crypto",
  "title": {
    "zh": "朝鲜黑客假扮招聘人员，感染了全球3万台设备",
    "en": "North Korean fake recruiters infect 30K devices, steal $10.7M in crypto"
  },
  "current_state": {
    "zh": "朝鲜黑客假扮招聘人员散布恶意软件，全球约3万台设备被感染。这是一场由国家支持、针对科技与加密货币行业求职者的攻击行动。\n\n此次行动表明，假招聘接触仍是与朝鲜有关联的攻击者获取初始访问权限的活跃途径，而这类行动此前已多次针对加密货币和科技领域的开发者。\n\n据报道，此次入侵是通过假招聘接触投递恶意软件所致，而非已确认的链上漏洞利用或交易所被攻破事件。",
    "en": "A multinational advisory from Japan, Germany, Australia and the US attributes a North Korean fake-recruiter malware campaign to hacking group WaterPlum, which infected at least 30,000 devices in over 100 countries and stole at least $10.7 million in crypto from developers and Web3 workers."
  },
  "first_seen_at": "2026-09-21T07:13:55.177935+00:00",
  "last_updated_at": "2026-09-24T09:26:28.100104+00:00",
  "last_material_change_at": "2026-09-21T07:13:55.177935+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 2,
  "entities": [
    "korean",
    "north",
    "north-korea"
  ],
  "identifiers": [],
  "topics": [
    "crypto-theft",
    "cybersecurity",
    "malware",
    "north-korea",
    "social-engineering"
  ],
  "updates": [
    {
      "update_id": "upd_a87bf688bdc40b1d",
      "event_id": "evt_0698c7a5520034f1",
      "occurred_at": "2026-09-21T01:42:53Z",
      "published_at": "2026-09-21T01:42:53Z",
      "first_seen_at": "2026-09-21T07:13:55.177935Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "朝鲜黑客假扮招聘人员，感染了全球3万台设备",
      "title_en": "North Korean fake recruiters infect 30K devices, steal $10.7M in crypto",
      "what_changed_zh": "朝鲜黑客假扮招聘人员散布恶意软件，全球约3万台设备被感染。这是一场由国家支持、针对科技与加密货币行业求职者的攻击行动。\n\n此次行动表明，假招聘接触仍是与朝鲜有关联的攻击者获取初始访问权限的活跃途径，而这类行动此前已多次针对加密货币和科技领域的开发者。\n\n据报道，此次入侵是通过假招聘接触投递恶意软件所致，而非已确认的链上漏洞利用或交易所被攻破事件。",
      "what_changed_en": "A multinational advisory from Japan, Germany, Australia and the US attributes a North Korean fake-recruiter malware campaign to hacking group WaterPlum, which infected at least 30,000 devices in over 100 countries and stole at least $10.7 million in crypto from developers and Web3 workers.",
      "current_state_zh": "朝鲜黑客假扮招聘人员散布恶意软件，全球约3万台设备被感染。这是一场由国家支持、针对科技与加密货币行业求职者的攻击行动。\n\n此次行动表明，假招聘接触仍是与朝鲜有关联的攻击者获取初始访问权限的活跃途径，而这类行动此前已多次针对加密货币和科技领域的开发者。\n\n据报道，此次入侵是通过假招聘接触投递恶意软件所致，而非已确认的链上漏洞利用或交易所被攻破事件。",
      "current_state_en": "A multinational advisory from Japan, Germany, Australia and the US attributes a North Korean fake-recruiter malware campaign to hacking group WaterPlum, which infected at least 30,000 devices in over 100 countries and stole at least $10.7 million in crypto from developers and Web3 workers.",
      "detailed_summary_zh": "A multinational advisory from Japan, Germany, Australia and the US attributes a North Korean fake-recruiter malware campaign to hacking group WaterPlum, which infected at least 30,000 devices in over 100 countries and stole at least $10.7 million in crypto from developers and Web3 workers.",
      "detailed_summary_en": "A multinational advisory from Japan, Germany, Australia and the US attributes a North Korean fake-recruiter malware campaign to hacking group WaterPlum, which infected at least 30,000 devices in over 100 countries and stole at least $10.7 million in crypto from developers and Web3 workers.",
      "background_zh": "被追踪为 Lazarus Group、APT38 和 TraderTraitor 的朝鲜相关团伙，已被美国联邦调查局公开认定与加密货币盗窃有关。Chainalysis 报告称，2025年加密货币被盗金额达到34亿美元，朝鲜相关活动仍是主要推动因素之一。WaterPlum（又称 Contagious Interview）和 Graphalgo 等其他行动，也通过假招聘对话和编程测试接触开发者。",
      "background_en": "DPRK-linked groups tracked as Lazarus Group, APT38 and TraderTraitor have been publicly attributed by the FBI to cryptocurrency theft. Chainalysis reported that crypto theft reached $3.4 billion in 2025, with DPRK activity persisting as a major driver. Separate campaigns such as WaterPlum (also called Contagious Interview) and Graphalgo have used fake recruiter conversations and coding tests to reach developers.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "对加密企业而言，风险敞口来自人员端而非链上：开发者终端被攻陷可能使其获得钱包、私钥和内部系统的访问权限，而进入构建流程的第三方代码则可能把供应链风险扩散到项目及其用户。",
      "market_impact_en": "For crypto firms, the exposure runs through the workforce rather than the chain: compromised developer endpoints can provide access to wallets, keys and internal systems, and third-party code pulled into build pipelines can propagate supply-chain risk to projects and their users.",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/",
          "title": "2025 Crypto Theft Reaches $3.4 Billion"
        },
        {
          "url": "https://www.reversinglabs.com/blog/graphalgo-campaign-respawned",
          "title": "Graphalgo fake recruiter malware campaign respawned | RL Blog"
        },
        {
          "url": "https://www.fbi.gov/news/press-releases/fbi-identifies-cryptocurrency-funds-stolen-by-dprk",
          "title": "FBI Identifies Cryptocurrency Funds Stolen by DPRK — FBI"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "rss:cointelegraph.com_rss:8bbf99dd423796d3",
        "gdelt:article:20260924T073000Z::https://www.thestar.com.my/tech/tech-news/2026/09/24/north-korean-hackers-posed-as-recruiters-they-infected-30000-devices-worldwide"
      ],
      "sources": [
        {
          "url": "https://cointelegraph.com/news/north-korean-fake-recruiters-infect-30k-devices-steal-107m-in-crypto?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound",
          "label": "Cointelegraph",
          "source_type": "rss",
          "official": false
        },
        {
          "url": "https://www.thestar.com.my/tech/tech-news/2026/09/24/north-korean-hackers-posed-as-recruiters-they-infected-30000-devices-worldwide",
          "label": "thestar.com.my",
          "source_type": "gdelt",
          "official": false
        }
      ]
    }
  ]
}
