시가총액: $2.7727T 4.18%
거래량(24시간): $112.9877B 43.32%
  • 시가총액: $2.7727T 4.18%
  • 거래량(24시간): $112.9877B 43.32%
  • 공포와 탐욕 지수:
  • 시가총액: $2.7727T 4.18%
암호화
주제
암호화
소식
cryptostopics
비디오
최고의 뉴스
암호화
주제
암호화
소식
cryptostopics
비디오
bitcoin
bitcoin

$81131.293825 USD

4.61%

ethereum
ethereum

$2629.223982 USD

5.70%

tether
tether

$0.999644 USD

0.06%

bnb
bnb

$762.001372 USD

0.94%

xrp
xrp

$1.419903 USD

7.09%

usd-coin
usd-coin

$0.999900 USD

0.01%

solana
solana

$111.987892 USD

5.89%

tron
tron

$0.337691 USD

0.55%

zcash
zcash

$1568.013373 USD

5.10%

hyperliquid
hyperliquid

$93.260937 USD

6.24%

dogecoin
dogecoin

$0.087155 USD

3.41%

monero
monero

$565.955936 USD

6.55%

chainlink
chainlink

$12.346409 USD

4.60%

cardano
cardano

$0.223297 USD

4.51%

unus-sed-leo
unus-sed-leo

$8.875656 USD

-0.19%

암호화폐 뉴스 기사

북한 해커들이 사기성 코딩 테스트를 통해 암호화폐 지갑을 노리고 있다고 당국이 경고했습니다.

2026/09/20 05:25

북한 해커들이 수천 개의 암호화폐 지갑을 훔치기 위해 가짜 채용 제안의 코딩 테스트를 악용함에 따라 전 세계에 경고가 발령되었습니다.

북한 해커들이 사기성 코딩 테스트를 통해 암호화폐 지갑을 노리고 있다고 당국이 경고했습니다.

Global Cyber Alert: North Korean Hackers Exploit Coding Tests to Target Crypto Wallets

글로벌 사이버 경고: 북한 해커들이 암호화폐 지갑을 표적으로 삼기 위해 코딩 테스트를 악용하고 있습니다.

In a stark warning issued on September 18, 2026, a coalition of seven international agencies, including the FBI and Japan's National Police Agency, revealed a sophisticated cyber campaign orchestrated by a North Korean threat group known as "WaterPlum" (also referred to as "Contagious Interview"). This operation, active between December 2025 and July 2026, has compromised at least 30,000 machines in over 100 countries, resulting in the theft of assets and credentials from more than 7,000 cryptocurrency wallets, amounting to an estimated $10.71 million USD.

2026년 9월 18일에 발표된 엄중한 경고에서 FBI, 일본 경찰청 등 7개 국제 기관 연합은 '워터플럼(WaterPlum)'으로 알려진 북한 위협 그룹이 조직한 정교한 사이버 캠페인('전염성 인터뷰'라고도 함)을 공개했습니다. 2025년 12월부터 2026년 7월까지 진행된 이 작전으로 인해 100개 이상의 국가에서 최소 30,000대의 컴퓨터가 손상되었으며, 그 결과 7,000개 이상의 암호화폐 지갑에서 자산과 자격 증명이 도난당했으며 그 규모는 미화 1,071만 달러로 추산됩니다.

The "Contagious Interview" Scheme: A Trojan Horse for Hackers

"전염성 인터뷰" 계획: 해커를 위한 트로이 목마

The modus operandi of WaterPlum is particularly insidious, preying on individuals seeking employment in the lucrative tech and cryptocurrency sectors. The hackers pose as recruiters from legitimate companies, initiating contact through social media, job boards, and freelance platforms. The bait? Attractive job offers in fields like AI, NFTs, and blockchain development.

WaterPlum의 작업 방식은 특히 수익성이 좋은 기술 및 암호화폐 부문에서 취업을 원하는 개인을 노리는 교활합니다. 해커들은 합법적인 회사의 채용 담당자로 가장하여 소셜 미디어, 채용 게시판, 프리랜스 플랫폼을 통해 접촉을 시작합니다. 미끼? AI, NFT 및 블록체인 개발과 같은 분야에서 매력적인 채용 정보를 제공합니다.

The cybercriminals meticulously guide potential victims through a seemingly standard hiring process, often employing AI-assisted face-swapping for video calls to enhance their deception. The critical juncture arrives during the technical interview or coding test phase. Candidates are instructed to download and execute files, ostensibly for the assignment or to resolve supposed technical glitches in communication tools. However, these files are malicious, serving as the entry point for malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.

사이버 범죄자는 겉으로는 표준적인 채용 프로세스를 통해 잠재적인 피해자를 세심하게 안내하며, 종종 AI 지원 얼굴 교환을 사용하여 화상 통화를 통해 속임수를 강화합니다. 기술 면접이나 코딩 테스트 단계에서 중요한 시점이 찾아옵니다. 응시자는 표면적으로는 과제를 위해 또는 통신 도구의 기술적 결함으로 추정되는 문제를 해결하기 위해 파일을 다운로드하고 실행하라는 지시를 받습니다. 그러나 이러한 파일은 악의적이며 BeaverTail, InvisibleFerret, OtterCookie, OtterCandy 및 StoatWaffle과 같은 악성 코드의 진입점 역할을 합니다.

The malware families are designed to grant attackers remote access, steal credentials stored in browsers, capture keystrokes and screenshots, and, most crucially for crypto holders, extract private keys and seed phrases from crypto wallets. The attack doesn't discriminate; it targets not just developers but also web designers and other freelance tech workers, recognizing that compromised service providers can lead to broader organizational breaches.

악성 코드군은 공격자에게 원격 액세스 권한을 부여하고, 브라우저에 저장된 자격 증명을 훔치고, 키 입력 및 스크린샷을 캡처하고, 암호화폐 보유자의 경우 가장 중요하게 암호화폐 지갑에서 개인 키와 시드 문구를 추출하도록 설계되었습니다. 공격은 차별하지 않습니다. 이는 개발자뿐만 아니라 웹 디자이너 및 기타 프리랜서 기술 직원도 대상으로 하며, 서비스 제공업체가 침해되면 더 광범위한 조직 침해로 이어질 수 있다는 점을 인식하고 있습니다.

Securing Your Digital Assets: A Crucial Divide

디지털 자산 보호: 중요한 격차

The joint advisory emphasizes a straightforward yet critical defense strategy: maintaining a strict separation between the machine used for running untrusted code and the device that stores your cryptocurrency keys. "Keep the machine on which you run other people's code strictly separate from the machine that holds your keys," the agencies implore.

공동 권고는 간단하면서도 중요한 방어 전략을 강조합니다. 즉, 신뢰할 수 없는 코드를 실행하는 데 사용되는 시스템과 암호화폐 키를 저장하는 장치를 엄격하게 분리하는 것입니다. "다른 사람의 코드를 실행하는 기계를 귀하의 키를 보관하는 기계와 엄격하게 분리해 두십시오"라고 기관은 간청합니다.

For developers, this means executing code assignments only within isolated environments like virtual machines or sandboxes. For crypto holders, the ultimate safeguard lies in hardware wallets, which ensure private keys never leave the device. The agencies also advise scrutinizing code for obfuscated or unreadable sections and being wary of specific command components like ".vscode/tasks.json" within project folders, especially if opened in editors like Visual Studio Code.

개발자의 경우 이는 가상 머신이나 샌드박스와 같은 격리된 환경 내에서만 코드 할당을 실행하는 것을 의미합니다. 암호화폐 보유자의 경우 궁극적인 보호 장치는 개인 키가 장치를 떠나지 않도록 보장하는 하드웨어 지갑에 있습니다. 또한 기관에서는 난독화되거나 읽을 수 없는 섹션에 대한 코드를 면밀히 조사하고 특히 Visual Studio Code와 같은 편집기에서 열 경우 프로젝트 폴더 내의 ".vscode/tasks.json"과 같은 특정 명령 구성 요소에 주의할 것을 권고합니다.

Beyond individual security, the advisory touches upon the concerning practice of "laptop farms"—locations where North Korean IT workers, often under false identities, operate compromised machines remotely. This highlights the broader implications for clients and companies, as engaging with or inadvertently supporting such operations can lead to breaches of national law and sanctions.

개인 보안 외에도 이 권고는 북한 IT 직원이 종종 허위 신원을 사용하여 손상된 시스템을 원격으로 작동하는 "노트북 농장"의 관행에 대해 다루고 있습니다. 이는 그러한 운영에 참여하거나 부주의하게 지원하는 것이 국내법 위반 및 제재로 이어질 수 있으므로 고객과 회사에 대한 더 광범위한 영향을 강조합니다.

Stay Vigilant, Stay Safe

경계심을 유지하고 안전을 유지하세요

The relentless evolution of cyber threats means constant vigilance is key. While the WaterPlum campaign is a significant development, it's a reminder that attackers are always refining their tactics. By understanding their methods and implementing robust security practices, especially the separation of devices for coding and crypto management, we can collectively build a stronger defense against these digital incursions. So, keep those coding tests in their own little digital sandbox and your crypto keys locked down tight – happy coding and happy holding!

사이버 위협이 끊임없이 진화함에 따라 지속적인 경계가 중요해졌습니다. WaterPlum 캠페인은 중요한 발전이지만, 이는 공격자가 항상 전술을 다듬고 있다는 점을 상기시켜 줍니다. 이들의 방법을 이해하고 강력한 보안 관행, 특히 코딩 및 암호화 관리를 위한 장치 분리를 구현함으로써 우리는 이러한 디지털 침입에 대한 강력한 방어를 종합적으로 구축할 수 있습니다. 따라서 코딩 테스트를 자체적인 작은 디지털 샌드박스에 보관하고 암호화 키를 단단히 잠가 두십시오. 즐거운 코딩과 즐거운 보유가 되십시오!

원본 소스:coinmarketcap

부인 성명:info@kdj.com

제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!

본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

2026年09月20日 에 게재된 다른 기사