時価総額: $2.7727T 4.18%
ボリューム(24時間): $112.9877B 43.32%
  • 時価総額: $2.7727T 4.18%
  • ボリューム(24時間): $112.9877B 43.32%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.7727T 4.18%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$81131.293825 USD

4.61%

ethereum
ethereum

$2629.223982 USD

5.70%

tether
tether

$0.999644 USD

0.06%

bnb
bnb

$762.001372 USD

0.94%

xrp
xrp

$1.419903 USD

7.09%

usd-coin
usd-coin

$0.999900 USD

0.01%

solana
solana

$111.987892 USD

5.89%

tron
tron

$0.337691 USD

0.55%

zcash
zcash

$1568.013373 USD

5.10%

hyperliquid
hyperliquid

$93.260937 USD

6.24%

dogecoin
dogecoin

$0.087155 USD

3.41%

monero
monero

$565.955936 USD

6.55%

chainlink
chainlink

$12.346409 USD

4.60%

cardano
cardano

$0.223297 USD

4.51%

unus-sed-leo
unus-sed-leo

$8.875656 USD

-0.19%

暗号通貨のニュース記事

北朝鮮のハッカー、虚偽のコーディングテストで仮想通貨ウォレットを標的に、当局が警告

2026/09/20 05:25

北朝鮮のハッカーが偽の求人票のコーディングテストを悪用し、数千の仮想通貨ウォレットから盗み出したため、世界規模の警報が発令された。

北朝鮮のハッカー、虚偽のコーディングテストで仮想通貨ウォレットを標的に、当局が警告

Global Cyber Alert: North Korean Hackers Exploit Coding Tests to Target Crypto Wallets

世界的なサイバー警報: 北朝鮮のハッカーがコーディングテストを悪用し、暗号通貨ウォレットを標的に

In a stark warning issued on September 18, 2026, a coalition of seven international agencies, including the FBI and Japan's National Police Agency, revealed a sophisticated cyber campaign orchestrated by a North Korean threat group known as "WaterPlum" (also referred to as "Contagious Interview"). This operation, active between December 2025 and July 2026, has compromised at least 30,000 machines in over 100 countries, resulting in the theft of assets and credentials from more than 7,000 cryptocurrency wallets, amounting to an estimated $10.71 million USD.

2026年9月18日に発せられた厳重な警告の中で、FBIや日本の警察庁を含む7つの国際機関の連合は、「ウォータープラム」(「伝染性インタビュー」とも呼ばれる)として知られる北朝鮮の脅威グループによって組織化された高度なサイバーキャンペーンを明らかにした。この作戦は 2025 年 12 月から 2026 年 7 月まで実施され、100 か国以上で少なくとも 30,000 台のマシンが侵害され、その結果、7,000 以上の仮想通貨ウォレットから資産と認証情報が盗まれ、その額は推定 1,071 万米ドルに達しました。

The "Contagious Interview" Scheme: A Trojan Horse for Hackers

「伝染性面接」スキーム: ハッカーのためのトロイの木馬

The modus operandi of WaterPlum is particularly insidious, preying on individuals seeking employment in the lucrative tech and cryptocurrency sectors. The hackers pose as recruiters from legitimate companies, initiating contact through social media, job boards, and freelance platforms. The bait? Attractive job offers in fields like AI, NFTs, and blockchain development.

ウォータープラムの手口は特に陰湿で、儲かるテクノロジー分野や仮想通貨分野での職を求める個人を食い物にしている。ハッカーは正規企業の採用担当者を装い、ソーシャルメディア、求人サイト、フリーランスプラットフォームを通じて接触を開始します。餌は? AI、NFT、ブロックチェーン開発などの分野での魅力的な求人。

The cybercriminals meticulously guide potential victims through a seemingly standard hiring process, often employing AI-assisted face-swapping for video calls to enhance their deception. The critical juncture arrives during the technical interview or coding test phase. Candidates are instructed to download and execute files, ostensibly for the assignment or to resolve supposed technical glitches in communication tools. However, these files are malicious, serving as the entry point for malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

サイバー犯罪者は、一見標準的な採用プロセスを通じて潜在的な被害者を細心の注意を払って誘導し、欺瞞を強化するためにビデオ通話に AI 支援の顔交換を使用することがよくあります。重要な分岐点は、技術面接またはコーディング テストの段階で起こります。受験者は、表向きは課題のため、またはコミュニケーション ツールで想定される技術的な問題を解決するために、ファイルをダウンロードして実行するように指示されます。ただし、これらのファイルは悪意があり、BeaverTail、InvisibleFerret、OtterCookie、OtterCandy、StoatWaffle などのマルウェアのエントリ ポイントとして機能します。

The malware families are designed to grant attackers remote access, steal credentials stored in browsers, capture keystrokes and screenshots, and, most crucially for crypto holders, extract private keys and seed phrases from crypto wallets. The attack doesn't discriminate; it targets not just developers but also web designers and other freelance tech workers, recognizing that compromised service providers can lead to broader organizational breaches.

このマルウェア ファミリは、攻撃者にリモート アクセスを許可し、ブラウザに保存されている認証情報を盗み、キーストロークやスクリーンショットをキャプチャし、さらに暗号通貨保有者にとって最も重要なことに、暗号通貨ウォレットから秘密キーとシード フレーズを抽出するように設計されています。攻撃は差別的ではありません。サービスプロバイダーの侵害が広範な組織侵害につながる可能性があることを認識しており、開発者だけでなく、Web デザイナーやその他のフリーランスの技術者も対象としています。

Securing Your Digital Assets: A Crucial Divide

デジタル資産の保護: 重要な分断

The joint advisory emphasizes a straightforward yet critical defense strategy: maintaining a strict separation between the machine used for running untrusted code and the device that stores your cryptocurrency keys. "Keep the machine on which you run other people's code strictly separate from the machine that holds your keys," the agencies implore.

共同勧告では、信頼できないコードの実行に使用されるマシンと暗号通貨キーを保存するデバイスとの間の厳密な分離を維持するという、単純だが重要な防御戦略を強調しています。 「他人のコードを実行するマシンと、鍵を保管するマシンを厳密に分離してください」と当局は懇願している。

For developers, this means executing code assignments only within isolated environments like virtual machines or sandboxes. For crypto holders, the ultimate safeguard lies in hardware wallets, which ensure private keys never leave the device. The agencies also advise scrutinizing code for obfuscated or unreadable sections and being wary of specific command components like ".vscode/tasks.json" within project folders, especially if opened in editors like Visual Studio Code.

開発者にとって、これは、仮想マシンやサンドボックスなどの隔離された環境内でのみコード割り当てを実行することを意味します。暗号通貨保有者にとっての究極の安全策は、秘密鍵がデバイスから決して流出しないようにするハードウェア ウォレットにあります。また各機関は、難読化されたセクションや判読不能なセクションのコードを精査し、特に Visual Studio Code などのエディターで開いた場合には、プロジェクト フォルダー内の「.vscode/tasks.json」などの特定のコマンド コンポーネントに注意するようアドバイスしています。

Beyond individual security, the advisory touches upon the concerning practice of "laptop farms"—locations where North Korean IT workers, often under false identities, operate compromised machines remotely. This highlights the broader implications for clients and companies, as engaging with or inadvertently supporting such operations can lead to breaches of national law and sanctions.

この勧告は、個人の安全を超えて、「ラップトップファーム」(北朝鮮のIT職員がしばしば偽りの身分で、侵害されたマシンを遠隔操作する場所)の懸念すべき慣行にも触れている。このことは、そのような業務に関与したり、不注意で支援したりすると、国内法の違反や制裁につながる可能性があるため、顧客や企業にとってより広範な影響を与えることを浮き彫りにしています。

Stay Vigilant, Stay Safe

警戒を怠らず、安全を保ちましょう

The relentless evolution of cyber threats means constant vigilance is key. While the WaterPlum campaign is a significant development, it's a reminder that attackers are always refining their tactics. By understanding their methods and implementing robust security practices, especially the separation of devices for coding and crypto management, we can collectively build a stronger defense against these digital incursions. So, keep those coding tests in their own little digital sandbox and your crypto keys locked down tight – happy coding and happy holding!

サイバー脅威の絶え間ない進化は、継続的な警戒が重要であることを意味します。 WaterPlum キャンペーンは重要な進展ですが、攻撃者が常に戦術を洗練していることを思い出させます。彼らの手法を理解し、堅牢なセキュリティ慣行、特にコーディングと暗号管理のためのデバイスの分離を実装することで、これらのデジタル侵入に対するより強力な防御を共同で構築することができます。したがって、コーディング テストを独自の小さなデジタル サンドボックスに保管し、暗号キーをしっかりとロックしてください。コーディングと保持は快適に行うことができます。

オリジナルソース:coinmarketcap

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年09月20日 に掲載されたその他の記事