|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
朝鲜黑客利用虚假工作机会中的编码测试从数千个加密钱包中窃取信息,引发全球警报。

Global Cyber Alert: North Korean Hackers Exploit Coding Tests to Target Crypto Wallets
全球网络警报:朝鲜黑客利用编码测试来瞄准加密钱包
In a stark warning issued on September 18, 2026, a coalition of seven international agencies, including the FBI and Japan's National Police Agency, revealed a sophisticated cyber campaign orchestrated by a North Korean threat group known as "WaterPlum" (also referred to as "Contagious Interview"). This operation, active between December 2025 and July 2026, has compromised at least 30,000 machines in over 100 countries, resulting in the theft of assets and credentials from more than 7,000 cryptocurrency wallets, amounting to an estimated $10.71 million USD.
在 2026 年 9 月 18 日发出的严厉警告中,包括联邦调查局 (FBI) 和日本国家警察厅在内的七个国际机构组成的联盟揭露了一个名为“WaterPlum”(也称为“传染性采访”)的朝鲜威胁组织精心策划的一场复杂的网络活动。该行动于 2025 年 12 月至 2026 年 7 月期间活跃,已破坏 100 多个国家/地区的至少 30,000 台机器,导致 7,000 多个加密货币钱包的资产和凭证被盗,价值估计达 1,071 万美元。
The "Contagious Interview" Scheme: A Trojan Horse for Hackers
“传染性采访”计划:黑客的特洛伊木马
The modus operandi of WaterPlum is particularly insidious, preying on individuals seeking employment in the lucrative tech and cryptocurrency sectors. The hackers pose as recruiters from legitimate companies, initiating contact through social media, job boards, and freelance platforms. The bait? Attractive job offers in fields like AI, NFTs, and blockchain development.
WaterPlum 的作案手法尤其阴险,专门针对在利润丰厚的科技和加密货币领域寻求就业的个人。黑客冒充合法公司的招聘人员,通过社交媒体、招聘网站和自由职业平台发起联系。诱饵?人工智能、NFT 和区块链开发等领域具有吸引力的工作机会。
The cybercriminals meticulously guide potential victims through a seemingly standard hiring process, often employing AI-assisted face-swapping for video calls to enhance their deception. The critical juncture arrives during the technical interview or coding test phase. Candidates are instructed to download and execute files, ostensibly for the assignment or to resolve supposed technical glitches in communication tools. However, these files are malicious, serving as the entry point for malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
网络犯罪分子通过看似标准的招聘流程精心引导潜在受害者,通常使用人工智能辅助的换脸视频通话来增强欺骗性。在技术面试或编码测试阶段,关键时刻到来。考生被指示下载并执行文件,表面上是为了完成作业或解决通信工具中所谓的技术故障。然而,这些文件是恶意的,充当 BeaverTail、InvisibleFerret、OtterCookie、OtterCandy 和 StoatWaffle 等恶意软件的入口点。
The malware families are designed to grant attackers remote access, steal credentials stored in browsers, capture keystrokes and screenshots, and, most crucially for crypto holders, extract private keys and seed phrases from crypto wallets. The attack doesn't discriminate; it targets not just developers but also web designers and other freelance tech workers, recognizing that compromised service providers can lead to broader organizational breaches.
这些恶意软件系列旨在授予攻击者远程访问权限,窃取浏览器中存储的凭据,捕获击键和屏幕截图,并且对于加密货币持有者来说最重要的是,从加密钱包中提取私钥和种子短语。攻击没有歧视;它不仅针对开发人员,还针对网页设计师和其他自由技术工作者,因为它认识到受到损害的服务提供商可能会导致更广泛的组织违规。
Securing Your Digital Assets: A Crucial Divide
保护您的数字资产:一个关键的鸿沟
The joint advisory emphasizes a straightforward yet critical defense strategy: maintaining a strict separation between the machine used for running untrusted code and the device that stores your cryptocurrency keys. "Keep the machine on which you run other people's code strictly separate from the machine that holds your keys," the agencies implore.
该联合咨询强调了一种简单而关键的防御策略:在用于运行不受信任代码的机器和存储加密货币密钥的设备之间保持严格的隔离。这些机构恳求道:“将运行他人代码的机器与保存您密钥的机器严格分开。”
For developers, this means executing code assignments only within isolated environments like virtual machines or sandboxes. For crypto holders, the ultimate safeguard lies in hardware wallets, which ensure private keys never leave the device. The agencies also advise scrutinizing code for obfuscated or unreadable sections and being wary of specific command components like ".vscode/tasks.json" within project folders, especially if opened in editors like Visual Studio Code.
对于开发人员来说,这意味着只能在虚拟机或沙箱等隔离环境中执行代码分配。对于加密货币持有者来说,最终的保障在于硬件钱包,它确保私钥永远不会离开设备。这些机构还建议仔细检查代码中是否存在模糊或不可读的部分,并警惕项目文件夹中的特定命令组件,例如“.vscode/tasks.json”,尤其是在 Visual Studio Code 等编辑器中打开时。
Beyond individual security, the advisory touches upon the concerning practice of "laptop farms"—locations where North Korean IT workers, often under false identities, operate compromised machines remotely. This highlights the broader implications for clients and companies, as engaging with or inadvertently supporting such operations can lead to breaches of national law and sanctions.
除了个人安全之外,该建议还涉及“笔记本电脑农场”的令人担忧的做法,即朝鲜 IT 工作人员经常以虚假身份远程操作受感染的机器的地方。这凸显了对客户和公司的更广泛影响,因为参与或无意中支持此类业务可能会导致违反国家法律和制裁。
Stay Vigilant, Stay Safe
保持警惕,保持安全
The relentless evolution of cyber threats means constant vigilance is key. While the WaterPlum campaign is a significant development, it's a reminder that attackers are always refining their tactics. By understanding their methods and implementing robust security practices, especially the separation of devices for coding and crypto management, we can collectively build a stronger defense against these digital incursions. So, keep those coding tests in their own little digital sandbox and your crypto keys locked down tight – happy coding and happy holding!
网络威胁的不断演变意味着持续保持警惕是关键。虽然 WaterPlum 活动是一个重大进展,但它提醒我们,攻击者总是在完善他们的策略。通过了解他们的方法并实施强大的安全实践,特别是编码和加密管理设备的分离,我们可以共同构建更强大的防御措施来抵御这些数字入侵。因此,将这些编码测试放在自己的小数字沙箱中,并将您的加密密钥牢牢锁定 - 快乐编码和快乐持有!
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- Polymarket 受到攻击:韩国打击非法赌博指控
- 2026-09-20 12:05:01
- 韩国当局正在对 Polymarket 用户提起刑事诉讼,引发了关于预测市场是否构成非法赌博或合法衍生品交易的争论。
-
-
- 在创纪录的网络活动中,Solana 价格飙升超过下降趋势线
- 2026-09-20 11:35:01
- 在前所未有的网络活动的推动下,Solana 的价格已突破关键的下降趋势线,这表明流行的区块链可能出现看涨转变。
-
-
-
-
-
- 加密货币市场热潮:KOL 聚焦老牌企业中的新兴机会
- 2026-09-20 07:25:01
- 主要行业声音和市场分析强调了不断发展的加密货币格局,重点关注早期潜力和现有资产的持久实力。
-

































