|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
北韓駭客利用假工作機會中的編碼測試從數千個加密錢包中竊取訊息,引發全球警報。

Global Cyber Alert: North Korean Hackers Exploit Coding Tests to Target Crypto Wallets
全球網路警報:北韓駭客利用編碼測試來瞄準加密錢包
In a stark warning issued on September 18, 2026, a coalition of seven international agencies, including the FBI and Japan's National Police Agency, revealed a sophisticated cyber campaign orchestrated by a North Korean threat group known as "WaterPlum" (also referred to as "Contagious Interview"). This operation, active between December 2025 and July 2026, has compromised at least 30,000 machines in over 100 countries, resulting in the theft of assets and credentials from more than 7,000 cryptocurrency wallets, amounting to an estimated $10.71 million USD.
在 2026 年 9 月 18 日發出的嚴厲警告中,包括聯邦調查局 (FBI) 和日本國家警察廳在內的七個國際機構組成的聯盟揭露了一個名為“WaterPlum”(也稱為“傳染性採訪”)的朝鮮威脅組織精心策劃的一場複雜的網絡活動。該行動於 2025 年 12 月至 2026 年 7 月期間活躍,已破壞 100 多個國家/地區的至少 30,000 台機器,導致 7,000 多個加密貨幣錢包的資產和憑證被盜,價值估計達 1,071 萬美元。
The "Contagious Interview" Scheme: A Trojan Horse for Hackers
「傳染性訪談」計畫:駭客的特洛伊木馬
The modus operandi of WaterPlum is particularly insidious, preying on individuals seeking employment in the lucrative tech and cryptocurrency sectors. The hackers pose as recruiters from legitimate companies, initiating contact through social media, job boards, and freelance platforms. The bait? Attractive job offers in fields like AI, NFTs, and blockchain development.
WaterPlum 的作案手法尤其陰險,專門針對在利潤豐厚的科技和加密貨幣領域尋求就業的個人。駭客冒充合法公司的招募人員,透過社群媒體、招募網站和自由工作平台發起聯繫。誘餌?人工智慧、NFT 和區塊鏈開發等領域具有吸引力的工作機會。
The cybercriminals meticulously guide potential victims through a seemingly standard hiring process, often employing AI-assisted face-swapping for video calls to enhance their deception. The critical juncture arrives during the technical interview or coding test phase. Candidates are instructed to download and execute files, ostensibly for the assignment or to resolve supposed technical glitches in communication tools. However, these files are malicious, serving as the entry point for malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
網路犯罪分子透過看似標準的招募流程精心引導潛在受害者,通常使用人工智慧輔助的換臉視訊通話來增強欺騙性。在技術面試或程式設計測驗階段,關鍵時刻到來。考生被指示下載並執行文件,表面上是為了完成作業或解決通訊工具中所謂的技術故障。然而,這些檔案是惡意的,充當 BeaverTail、InvisibleFerret、OtterCookie、OtterCandy 和 StoatWaffle 等惡意軟體的入口點。
The malware families are designed to grant attackers remote access, steal credentials stored in browsers, capture keystrokes and screenshots, and, most crucially for crypto holders, extract private keys and seed phrases from crypto wallets. The attack doesn't discriminate; it targets not just developers but also web designers and other freelance tech workers, recognizing that compromised service providers can lead to broader organizational breaches.
這些惡意軟體系列旨在授予攻擊者遠端存取權限,竊取瀏覽器中儲存的憑證,捕獲擊鍵和螢幕截圖,並且對於加密貨幣持有者來說最重要的是,從加密錢包中提取私鑰和種子短語。攻擊沒有歧視;它不僅針對開發人員,還針對網頁設計師和其他自由技術工作者,因為它認識到受到損害的服務提供者可能會導致更廣泛的組織違規。
Securing Your Digital Assets: A Crucial Divide
保護您的數位資產:一個關鍵的鴻溝
The joint advisory emphasizes a straightforward yet critical defense strategy: maintaining a strict separation between the machine used for running untrusted code and the device that stores your cryptocurrency keys. "Keep the machine on which you run other people's code strictly separate from the machine that holds your keys," the agencies implore.
該聯合諮詢強調了一種簡單而關鍵的防禦策略:在用於運行不受信任代碼的機器和儲存加密貨幣金鑰的設備之間保持嚴格的隔離。這些機構懇求道:“將運行他人代碼的機器與保存您密鑰的機器嚴格分開。”
For developers, this means executing code assignments only within isolated environments like virtual machines or sandboxes. For crypto holders, the ultimate safeguard lies in hardware wallets, which ensure private keys never leave the device. The agencies also advise scrutinizing code for obfuscated or unreadable sections and being wary of specific command components like ".vscode/tasks.json" within project folders, especially if opened in editors like Visual Studio Code.
對於開發人員來說,這意味著只能在虛擬機器或沙箱等隔離環境中執行程式碼分配。對於加密貨幣持有者來說,最終的保障在於硬體錢包,它確保私鑰永遠不會離開裝置。這些機構還建議仔細檢查程式碼中是否存在模糊或不可讀的部分,並警惕專案資料夾中的特定命令元件,例如“.vscode/tasks.json”,尤其是在 Visual Studio Code 等編輯器中開啟時。
Beyond individual security, the advisory touches upon the concerning practice of "laptop farms"—locations where North Korean IT workers, often under false identities, operate compromised machines remotely. This highlights the broader implications for clients and companies, as engaging with or inadvertently supporting such operations can lead to breaches of national law and sanctions.
除了個人安全之外,該建議還涉及「筆記型電腦農場」的令人擔憂的做法,即北韓 IT 工作人員經常以虛假身份遠端操作受感染的機器的地方。這凸顯了對客戶和公司的更廣泛影響,因為參與或無意中支持此類業務可能會導致違反國家法律和製裁。
Stay Vigilant, Stay Safe
保持警惕,保持安全
The relentless evolution of cyber threats means constant vigilance is key. While the WaterPlum campaign is a significant development, it's a reminder that attackers are always refining their tactics. By understanding their methods and implementing robust security practices, especially the separation of devices for coding and crypto management, we can collectively build a stronger defense against these digital incursions. So, keep those coding tests in their own little digital sandbox and your crypto keys locked down tight – happy coding and happy holding!
網路威脅的不斷演變意味著持續保持警惕是關鍵。雖然 WaterPlum 活動是一個重大進展,但它提醒我們,攻擊者總是在完善他們的策略。透過了解他們的方法並實施強大的安全實踐,特別是編碼和加密管理設備的分離,我們可以共同建立更強大的防禦措施來抵禦這些數位入侵。因此,將這些編碼測試放在自己的小數位沙箱中,並將您的加密密鑰牢牢鎖定 - 快樂編碼和快樂持有!
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
-
-
- 在創紀錄的網路活動中,Solana 價格飆升超過下降趨勢線
- 2026-09-20 11:35:01
- 在前所未有的網路活動的推動下,Solana 的價格已突破關鍵的下降趨勢線,這表明流行的區塊鏈可能出現看漲轉變。
-
-
-
-
-
- 加密貨幣市場熱潮:KOL 聚焦老牌企業中的新興機會
- 2026-09-20 07:25:01
- 主要行業聲音和市場分析強調了不斷發展的加密貨幣格局,重點關注早期潛力和現有資產的持久實力。
-

































