BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%
BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%

malware

All
Article
Flash

Japan National Police Agency: North Korea's cyber attack organization WaterPlum launched a large-scale attack targeting IT technicians

According to a joint alert issued by the Japanese National Police Agency, FBI, ASD/ACSC, BND, and BfV, the North Korean-backed cyber attack organization "WaterPlum" (also known as Contagious Interview) targets job seekers by disguising itself as an AI, cryptocurrency, and NFT company to post fake job listings. This lures job seekers into downloading NPM packages containing malware such as BeaverTail, InvisibleFerret, and OtterCookie, which then steal cryptocurrency wallet information and confidential data.As of July 2026, the organization has infected over 30,000 devices in more than 100 countries and regions worldwide, stealing information from over 7,000 cryptocurrency wallets, with the wallets under its control receiving at least approximately 1.7 billion yen (about 10.71 million USD) in cryptocurrency. The Japanese National Police Agency has discovered and dismantled a "notebook farm" established by local "supporters" for the first time in the country, where North Korean IT laborers remotely control PCs within the supporters' residences to conduct business, with the related amount involved reaching several hundred million yen.The police and FBI assess that WaterPlum and some North Korean IT laborers are under the unified command of the 313 Bureau of the Ministry of Military Industry of the Workers' Party of Korea, with the profits directly flowing into North Korea's national funding pool. The police remind IT technicians and corporate issuers to remain vigilant and avoid executing third-party code in unverified environments.

first_img Chainalysis: North Korea and Iran hackers drive a 420% surge in on-chain malware writing volume

According to Cointelegraph, a report by Chainalysis shows that in the past 12 months, the number of times attackers stored malware instructions or infrastructure information on public blockchains has surged by 420%, with state-sponsored hackers contributing about two-thirds of the new activity each quarter. Chainalysis linked previously unattributed activities on Tron, Aptos, and BNB Smart Chain to the North Korean-backed organization UNC5342.The report points out that the encoded pointers in Tron and Aptos transactions direct infected devices to the same BSC transaction, which contains encrypted server addresses and configuration data used to connect to remote access and data theft infrastructure. Information on public blockchains remains accessible even after domain names, servers, or code repositories are shut down, enhancing the persistence of malware activities. In 2025, North Korean hackers used similar technology called EtherHiding to implant coin theft code into smart contracts.Additionally, since July 2025, the volume of malicious blockchain writes has increased by 440%, when high-capacity open-source Chinese AI models began to have the ability to generate malicious code. Eric Jardine, head of cybercrime research at Chainalysis, stated that a clear temporal correlation was found, but it could not be proven that the attackers used these models.Chainalysis also identified threat actors suspected of being linked to the Iranian Ministry of Intelligence, writing encoded command and control routing data into the Bitcoin blockchain and sending small payments to well-known addresses historically associated with Satoshi Nakamoto, which are unrelated to the attackers and serve only as a permanent public location for infected devices to receive update instructions.

first_img HBO Max account was hijacked, and 108 malicious ads were placed to steal cryptocurrency assets

Cybersecurity company Hudson Rock disclosed that the Reddit verified account of the streaming service HBO Max was hijacked earlier this month and deployed 108 malicious ads within approximately 48 hours. These ads used a non-existent HBO Max native macOS application as bait, luring users to open Terminal or PowerShell and paste malicious commands, a technique known as ClickFix.Researchers named this operation PasteSwitch, and its delivery system adapts based on the visitor's device and the advertised software. Observed Mac payloads include MacSync and Atomic macOS (AMOS) information-stealing trojans, targeting browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases. The malware also utilized Binance Smart Chain contracts as variable C2 address delivery points and was associated with a cryptocurrency clipboard hijacker that replaces clipboard wallet addresses.According to Malwarebytes, Reddit administrators have suspended the related ads and initiated a security investigation following reports. The report did not specify how the account was compromised or the number of victims, nor was there evidence found that the HBO Max streaming service itself was breached. The ClickFix technique has previously been used multiple times in attacks targeting cryptocurrency users, including approximately 2,000 compromised WordPress sites and malicious activities disguised as CAPTCHA.

A man in the United States implanted malware through Steam games to steal cryptocurrency assets, infecting about 8,000 devices

The U.S. federal prosecutors have charged a 21-year-old Florida man, Zyaire Wilkins, accusing him of implanting malware to steal cryptocurrency assets in at least 8 games with accomplices between May 2024 and February 2026, spreading it through gaming platforms, resulting in approximately 8,000 devices being infected and about 80 cryptocurrency wallets being stolen, with the amount involved exceeding $220,000.The indictment documents show that the games involved include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova. Some of these games had previously been removed from Steam due to security risks. Investigators stated that the suspect promoted these games through platforms such as Discord, Telegram, X, and LinkedIn, luring users to download and install them, after which the malware stole sensitive information from victims and siphoned off cryptocurrency wallet assets.The FBI indicated that law enforcement identified the suspect through on-chain fund flow analysis and digital payment records. The investigation found that his associated cryptocurrency wallet had purchased over 150 gift cards on the cryptocurrency gift card platform Bitrefill, including Uber Eats gift cards, ultimately helping investigators confirm his phone number and address. The case has now been filed in the U.S. District Court for the Western District of Washington.
app_icon
ChainCatcher Building the Web3 world with innovations.