Post

North Korean Cyber Actor Group Targeting IT Professionals

North Korean Cyber Actor Group Targeting IT Professionals

North Korean Cyber Actor Group Targeting IT Professionals

The North Korean “WaterPlum” cyber actor group, commonly referred to as “Contagious Interview,” conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries. The NPA and the FBI assess that both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.

WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities. They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services. WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets. WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK). Additionally, some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients.

WaterPlum actors recruit job seekers internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces. During the recruitment cycle, WaterPlum actors require job seekers to participate in technical online virtual interviews or complete technical coding assignments. During interviews, WaterPlum actors instruct job seekers to download and execute malicious files, hosted on multiple online collaboration software developer platforms and code repositories, to complete a coding assignment or troubleshoot an error in the online video conferencing platform. WaterPlum actors upload malicious Node Package Manager (NPM) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle malware and related variants. Once WaterPlum actors obtain backdoor access to victim computer networks through malicious loader downloads, they use Remote-Access Trojans (RATs) to preserve connectivity, persistence, and pathways to pivot across victim systems. The actors use infostealers to exfiltrate the victim’s sensitive data and cryptocurrency to a Command-and-Control (C2) IP address for remote management of infected devices or networks.

WaterPlum actors employ international enablers within Japan, the United States, and other countries to set up and manage “laptop farms” for remote device management. Enablers also create and manage virtual private servers (VPS) on the WaterPlum actors’ behalf, obfuscating the actors’ physical work locations while they perform contracted IT work and generate revenue. Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments. Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency. Other sensitive data targeted for exfiltration includes: Authentication data stored in web browsers; Clipboard information, key-logs, screenshots; and Cryptocurrency-wallet data.

For the first time in Japan, authorities successfully identified, investigated, and dismantled a “laptop farm” operated by an enabler in Japan. Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan. The FBI continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers. IT professionals in Japan and the United States – and businesses that outsource or commission work via crowdsourcing or other means – are encouraged to refer to the TTPs and mitigation measures below and implement appropriate security controls.

Read full article

This post is licensed under CC BY 4.0 by the author.