North Korea Robbed an Exchange and Thirty Thousand Developers in the Same Week. The Exchange Got the Headlines. The Developers Are the Front Door.
Two North Korean money stories landed eight days apart this month, and they are the same story told at two sizes. On September 18, police and intelligence agencies from Japan, the United States, Australia and Germany published a joint advisory on WaterPlum, the group most of the industry calls Contagious Interview: 30,000 infected machines in more than 100 countries, 7,000 cryptocurrency wallets drained, 10.71 million dollars sent home. On September 24, the exchange Bitget lost somewhere between 351.6 and 387.5 million dollars from its hot wallets, and by the next morning its CEO was saying North Korea was "very likely" behind it.
The exchange heist is the one that makes headlines. The fake job interview is the one aimed at you, and it is the one a cash-poor defender can actually do something about on Monday.
The retail operation: WaterPlum and the fake job interview
The joint advisory, signed by Japan's National Police Agency and National Cybersecurity Office, the FBI, the Defense Cyber Crime Center, ASD's ACSC, the BND and the BfV, assesses WaterPlum and some North Korean IT workers as operating under the 313 General Bureau of the Munitions Industry Department. The playbook hasn't changed in years because it doesn't need to. A recruiter who looks like an AI, crypto or NFT company reaches out through LinkedIn, a job board, a freelance marketplace or Discord. The interview includes a coding assignment, or a "fix this error in the video call software" moment. The candidate clones a repository and runs it.
The repository carries BeaverTail, InvisibleFerret, OtterCookie, OtterCandy or StoatWaffle, depending on the season. Between December 2025 and July 2026, the agencies count at least 30,000 machines, mostly belonging to individual web designers, engineers and crypto or Web3 specialists. What leaves those machines is the full kit: browser-saved passwords, keystrokes, screenshots, wallet seed phrases, and ID photos that North Korean IT workers then reuse to pose as the victims and get hired.
The advisory has no indicators in it. It's a behavior document, and a good one. For network indicators we went to the researchers who published them.
Kudelski Security published a full teardown on June 30 of a fake interview built around a trojanized blockchain project called Ajuna-solution. It impersonates the real Swiss company Ajuna Network. Running npm install, or just opening the folder in VS Code and trusting it, fires a tasks.json that reaches out to a Hetzner server at 138.201.128.169 on port 1224. Kudelski also documented the operators' use of Astrill VPN exit nodes in the US and Japan, and shipped Suricata and YARA rules.
NTT Security (Rintaro Koike, translated by Ryu Hiyoshi) published StoatWaffle on March 17. It is the modular Node.js loader, stealer and RAT that WaterPlum's "Team 8" moved to around December 2025, which is exactly the start of the advisory's 30,000-machine window. StoatWaffle abuses VS Code's runOn folderOpen setting, so the code runs the moment a victim opens and trusts the project. No install step is needed.
Silent Push covered the other half of the business on September 14. A North Korean IT worker calling himself "Tec Guru" was posting on a mouse-review Discord server to recruit people in the US, EU and Latin America to sit on camera for job interviews while he did the technical work remotely, split 65/35 in his favor. He recommended Astrill VPN.
The wholesale operation: Bitget
Bitget says its systems flagged unauthorized transfers from a limited number of hot and warm wallets at 18:31 UTC on September 24. The attackers didn't steal a private key. They compromised a wallet backend system, fabricated transfer data, and got Bitget's own signing process to approve the withdrawals. The exchange's user protection fund, which holds more than 464 million dollars, covers the loss. Mandiant and SlowMist are investigating.
The attribution so far rests on three things. First, Bitget CEO Gracy Chen's statement about IP behavior tied to VPN infrastructure with a history of North Korean use. Second, SlowMist's MistTrack tracing of the proceeds across 11 EVM, 7 XRP Ledger and 1 TRON addresses. Third, an observation by MetaMask's Taylor Monahan that funds from Bitget landed in an address that previously received funds stolen from Bybit. That is strong circumstantial attribution. It is not yet a government attribution, and we'll say so until there is one. The first-hop address, which Etherscan tags as Bitget Exploiter 1, is 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee.
Why these belong in the same post
The mechanics rhyme. At Bitget the attackers got a trusted system to sign something it shouldn't have. In WaterPlum's case they got a trusted person to run something they shouldn't have. Neither needed a novel exploit. Both went after the step where an authorized process says yes.
The money rhymes too. The retail operation pulls from thousands of individuals at a few thousand dollars each. The wholesale operation pulls hundreds of millions from one backend. North Korean crypto theft in 2026 has now passed a billion dollars, and the retail side is what builds the access and identities the wholesale side needs. A developer infected through a fake interview is also a developer whose employer now has a problem.
And the supply-chain door is the same door. Earlier today we covered Graphalgo, where Aikido tied DPRK-overlapping operators to malicious npm packages and Terraform providers, with a blockchain contract used as a dead drop for C2. Fake interview repos, poisoned packages and trojanized providers are three delivery methods from one national program.
What our feed held, and what it didn't
We checked every indicator against our own corpus before writing this.
The Kudelski C2 IP, 138.201.128.169, was already in our index. It arrived through the TweetFeed community feed on July 15, at confidence 70, with no actor or family attached. That was fifteen days after Kudelski published, so this is redistribution of their finding, not a detection of ours. At confidence 70 it sat below the confidence 80 floor that our edge shield blocks at, so we held it and didn't act on it. We have now re-tagged it to WaterPlum at 85, citing Kudelski.
The five StoatWaffle C2 IPs NTT published in March were not in our corpus at all. We missed them for six months. We are adding them now at confidence 75, below the 80 our own edge shield blocks at. A VPS address that served C2 in March has a good chance of belonging to somebody innocent in September. They are in our default CSV, so if you block everything at the default threshold, you will block these too. If you would rather hunt than block, pull the feed with min_confidence=80 and search your logs for these five by hand.
The Bitget exploiter address was not in our corpus. It is now, as a chain-address record at confidence 90, for exchanges and OTC desks screening deposits. It is not a network indicator and won't show up in ips.csv.
Our adversaries index has a Lazarus profile and several Chollima entries, but searches for Famous Chollima, WaterPlum and Contagious Interview did not surface a dedicated profile. A zero on a name search is not proof of absence, but it's thin, and we're treating it as a gap to fill. We did cover this group's AI-assisted stealer in Famous Chollima Got Claude to Co-Author Their Crypto Stealer.
Monday morning, for a cash-poor defender
If you are a developer looking for work, never run an interview assignment on the machine that holds your wallet, your password manager or your employer's access. Use a throwaway VM or a disposable cloud workspace. A company that won't let you do that is telling you something.
Turn off automatic task execution in VS Code. Set task.allowAutomaticTasks to off, and read .vscode/tasks.json in any repository before you trust the folder. StoatWaffle and the Kudelski sample both fire from that file.
Before running npm install in a stranger's repository, read package.json, including the scripts section and the preinstall and postinstall hooks. Check every dependency name against a deny-list. Ours is free through the check-package tool on our MCP server and as packages.json for CI.
Treat a command containing curl, base64, -enc, mshta, Invoke-WebRequest or iwr, or hidden, in anything an interviewer asks you to run, as a stop sign. That list comes straight from the advisory.
If you think you ran one, disconnect, assume your wallets are gone, create a new wallet on a different device, move what's left, and rebuild the machine. The advisory says the same, and it's right.
If you hire remote engineers, verify that the applicant's IP roughly matches where they say they live, call the phone number, ask about their hometown and the weather, and be suspicious of anyone who wants to be paid in crypto or into someone else's account. Those checks come from the advisory's section on applicants at a Japanese exchange, and they're free.
If you run an exchange or OTC desk, screen deposits against the Bitget exploiter address and follow SlowMist and MistTrack's published address set as it grows.
Indicators
WaterPlum / Contagious Interview, per Kudelski Security (June 30): 138.201.128.169 (C2, Hetzner, port 1224) and the check-in URL http://138.201.128.169:1224/api/checkStatus. Trojanized repository name: Ajuna-solution.
StoatWaffle C2, per NTT Security (March 17), at confidence 75 as intel, not for blocking: 185.163.125.196, 147.124.202.208, 163.245.194.216, 66.235.168.136, 87.236.177.9.
Recruiting persona, per Silent Push (September 14): Discord tecguru113, Telegram Tecguru0618.
Bitget heist, first-hop EVM address tagged Bitget Exploiter 1: 0x770b10b273fC44Fe9197D6bF20F145c2e98463Ee.
All eight records are in our feed as manual-batch-waterplum-contagious-2026-09 and manual-batch-bitget-heist-2026-09, with the primary research linked on every record. The six IPs and the payload URL are in the default CSV blocklists. The exploiter wallet address is in our index, but no CSV blocklist has a type for a wallet, and it should be in our MISP feed and is not yet: while checking this post we found the MISP feed's event selection was dropping small new campaigns, nine of today's ten included. The fix is written and ships with our next deploy. The five StoatWaffle IPs are the ones at 75; min_confidence=80 leaves them out.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=north-korea-robbed-an-exchange-and-thirty-thousand-developers-in-the-same-week-the-exchange-got-the




Comments