Skip to content
HackInvasionCybersecurity Knowledge Hub

Daily Cyber Threat Brief — September 27, 2026: Bitget Hackers Drain $351.6M; North Korea Suspected

🗂️ CASE FILE — September 27, 2026

Lead story: Crypto exchange Bitget disclosed that attackers drained approximately $351.6 million from hot and warm wallets on September 24 — without ever compromising a private key. The attackers reportedly compromised a backend wallet system and used it to spoof transfer data through Bitget's own authorization-signing process. CEO Gracy Chen said the attack is "consistent with techniques used by DPRK-linked hacker groups," and blockchain intelligence firm Elliptic assessed DPRK attribution as "highly likely." The theft pushes Elliptic's tracked total for suspected North Korean crypto heists in 2026 past $1 billion.

Also covered: Japan's Keio Corporation confirms a ransomware incident hit group servers on September 26, while rail operations continue unaffected · The multi-agency WaterPlum / Contagious Interview advisory details 30,000 infected devices across 100+ countries and $10.7M funneled to North Korea · Ransomware leak-site claims roundup: Everest names Securitas Group, Storm claims Applied Composites and Magna Legal Services, thegentlemen claims Montreal-based Metalware Corporation.

Sources: 7 linked at the end of this brief.

Today's top stories

Two North Korea-linked threads dominate the threat picture this week. The Bitget heist — one of the largest centralized-exchange exploits of 2026 — was executed not by stealing keys but by tricking the exchange's own signing infrastructure into approving fraudulent transfers, a technique that should make every CEX security team uncomfortable. Meanwhile, the joint Japan–US–Australia–Germany advisory on WaterPlum (Contagious Interview) documents the industrial-scale mechanics behind that same regime's long game: fake job interviews, malicious NPM packages, and 30,000 infected developer machines. Elsewhere, Keio Corporation joined the confirmed-victim list after ransomware hit group corporate systems, and a cluster of unverified leak-site claims named targets from a Swedish security giant to a Montreal manufacturer.

Bitget: $351.6M drained via spoofed backend transfers; DPRK suspected, no private keys taken

Bitget's eighth anniversary celebrations were cut short late on September 24, when wallets tagged as belonging to the Seychelles-registered exchange began bleeding funds across multiple chains. Arkham analyst Emmett Gallic flagged the outflows publicly more than an hour before Bitget said anything; by the time CEO Gracy Chen confirmed the incident on X, roughly $183 million had already moved. The final tally: approximately $351.6 million (some analyses put it as high as $387 million once all impacted wallets are counted).

The technical detail is the story here. Chen stated the attack was detected at 18:31 UTC on September 24 and that the breach was confined to Bitget's hot and warm wallet layers — cold storage, held offline, was never touched. More importantly, "private key compromise has been ruled out." Instead, the attackers compromised a backend system within Bitget's wallet infrastructure, used it to spoof transfer data, and rode that forged data straight through the exchange's own authorization-signing process. The system approved transactions it should never have seen.

Stolen assets moved across at least seven networks — Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base — covering ETH, XRP (roughly 40% of the haul), BNB, AVAX, USDT, and USDC. Arkham tracked a burst in which $228 million left Bitget in just 18 minutes. Withdrawals were frozen; deposits and trading continued. Chen pledged that the loss falls within the coverage of Bitget's User Protection Fund (over $464 million) and that customer balances remain accurate.

On attribution: Elliptic assessed on September 25 that "multiple indicators suggest the over $350 million exploit is highly likely to be linked to the DPRK," noting the incident pushes its tracked total of suspected North Korean cryptoasset theft in 2026 past $1 billion. Chen told Reuters that investigators identified IP addresses tied to VPN services previously used by a North Korean hacking group and that the attack pattern resembled earlier DPRK-attributed operations. The specific initial-access vector is still under technical investigation; Bitget says the vulnerability has been fixed and it is working with Mandiant and SlowMist on the probe. Context: last year's Bybit hack ($1.5 billion) was attributed by the FBI to North Korean actors — the playbook is now industrialized.

🔍 Investigation notes — defender takeaway (click to expand)

The Bitget case reframes exchange threat modeling. The industry hardened key management after years of wallet compromises; attackers responded by attacking the trust boundary between backend systems and signing workflows instead. If a backend service can feed fraudulent-but-well-formed transfer requests to an authorization process that trusts them implicitly, key custody becomes irrelevant. Defenders running signing infrastructure should: (1) treat transfer-data integrity as a separate control from key custody — enforce out-of-band validation of transfer parameters before signing; (2) instrument anomaly detection on signing authorization velocity and value (the $228M/18min burst is the kind of deviation that should trip a circuit breaker); (3) assume DPRK-linked actors target crypto-adjacent employment and vendor relationships too — this is the same regime running Contagious Interview against developers (see next story). Monitor wallet-drain IOEs across chains via labeled exploit addresses (Elliptic published labels shortly after first alerts).

Keio Corporation confirms ransomware hit on group servers; rail operations unaffected

Keio Corporation, one of Japan's major railway and transportation groups, confirmed that ransomware affected Keio Group servers on the morning of September 26. The incident disrupted some business systems used by companies within the wider Keio Group, but the company said its railway operations were not affected — the separation between railway infrastructure and impacted corporate systems appears to have prevented the intrusion from disrupting train services.

Keio said it detected the ransomware activity in the early hours of September 26, isolated affected network environments to contain spread, notified law enforcement, and brought in external specialists. At this stage the confirmed facts are narrow: no ransomware group name, no exfiltration volume, and no disruption timeline have been disclosed. A data-exposure investigation is underway. The rail-group case is a useful segmentation success story — whatever network isolation exists between Keio's corporate IT and its railway control systems appears to have held under real pressure.

🔍 Investigation notes — defender takeaway (click to expand)

Segmentation between enterprise IT and operational technology is the headline defensive lesson, and it held here. What remains unknown is the more important question for incident responders: was exfiltration part of the attack? Double-extortion groups routinely encrypt first and disclose theft later; the company's confirmation of ransomware without a named actor or data-impact statement is consistent with early-stage containment. Treat the next Keio disclosure as the one that will matter for third parties (partner organizations, customer data). Until then: review OT/IT segmentation boundaries, verify that backup and recovery of corporate systems does not depend on the same network segments that are likely to be isolated during containment, and confirm ransomware playbooks include law-enforcement notification and external IR retainer activation within hours, not days.

WaterPlum / Contagious Interview: joint advisory documents 30,000 infected devices, $10.7M to North Korea

A joint cybersecurity advisory published September 18 by Japan's National Police Agency and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center, Australia's Cyber Security Centre, and Germany's BND and BfV attributes a long-running hiring-scam campaign to a North Korean group it calls WaterPlum — the industry's "Contagious Interview" cluster.

The numbers are industrial: between roughly December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries. Funds or account credentials were taken from over 7,000 cryptocurrency wallets, and an estimated ¥1.7 billion (about $10.71 million) was transferred to North Korea. The NPA and FBI assess that WaterPlum operators and some North Korean IT workers answer to the same command: the 313 General Bureau of the Munitions Industry Department, under the Workers' Party of Korea's Central Committee — and both operations were observed using the same IP addresses to access laptop farms and apply for jobs.

The infection vector is social engineering at scale. Actors posed as recruiters for AI, crypto, and NFT companies on social media, job boards, and freelance platforms, then walked candidates through fake technical interviews in which victims were told to download and run files — including malicious NPM packages seeded with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. StoatWaffle arrived in blockchain-themed Visual Studio Code projects that execute code once the victim trusts the folder. Post-infection tooling harvested browser credentials, keystrokes, screenshots, wallet private keys and seed phrases, and ID documents — and gave the actors a path into victims' employers' networks. The advisory also notes Japan's first-ever takedown of a North Korean laptop farm.

🔍 Investigation notes — defender takeaway (click to expand)

This is the supply chain you forget about: your employees' job searches. Primary targets were developers and Web3 specialists — exactly the people with credentials into build pipelines, cloud consoles, and signing infrastructure. The bridge from this advisory to the Bitget story is the shared command structure and shared IP infrastructure: the same 313 General Bureau ecosystem behind the wallets-drained-by-fake-interview operation is the ecosystem behind the $350M exchange heist. Defender actions: (1) VS Code Restricted Mode for untrusted projects and mandatory tasks.json review before execution — the advisory specifically calls this out; (2) hunt for the named payload families (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) and NPM typosquatting in developer environments; (3) treat compromised personal devices of remote staff as a lateral-movement path into corporate networks — this campaign is explicitly dual-purpose, theft plus enterprise access.

Ransomware leak-site claims roundup: Securitas, Applied Composites, Magna Legal Services, Metalware

A cluster of new leak-site listings surfaced over September 26–27. None are independently confirmed; treat each as a threat-actor claim, not a confirmed breach:

  • Everest names Securitas Group. The Swedish security-services multinational appeared on Everest's leak site on September 25 (~16:29 UTC), per threat-intelligence monitoring. No ransom demand, data volume, or samples disclosed; no confirmation from Securitas. A security vendor on a leak site is worth watching — such companies hold client-site and credential data across many customers.
  • Storm claims Applied Composites. The U.S. aerospace/defense manufacturer appeared on Storm's listings on September 27. The company makes advanced composite components for aerospace, defense, and space customers — engineering data would be high-value for double extortion. Scope and data theft unconfirmed.
  • Storm claims Magna Legal Services. The Philadelphia litigation-support provider (court reporting, depositions, case management for law firms, insurers, and government agencies) was reportedly listed September 27. Disruption to time-sensitive legal services is the immediate risk.
  • thegentlemen claims Metalware Corporation. The Montreal-based manufacturer of industrial steel shelving was reportedly listed September 27, with operational disruption claimed in Canada. The Gentlemen emerged around mid-2025 and now lists 800+ victims across 86 countries; ESET reported in June that the gang uses an EDR killer dubbed "GentleKiller."
  • Arcus claims Pantaneiro Capas; m3rx claims Cipher.Systems; Barracuda claims International Chemical Co. — ThreatMon-reported listings from September 26–27 with no confirmed compromise.
🔍 Investigation notes — defender takeaway (click to expand)

Leak-site appearances are early-warning telemetry, not verdicts: groups post claims before or without confirmed encryption, and some victims never appear in public reporting. The defensive value is in the pattern — Storm hitting both an aerospace supplier and a legal-services provider in one weekend suggests opportunistic, access-driven targeting rather than sector campaigns. For defenders: if any of these organizations are in your third-party ecosystem, escalate monitoring on vendor VPN/EDR telemetry and ask for their incident communications proactively rather than waiting for a public statement. And if you run the same manufacturing vertical as Metalware (industrial shelving, fabrication), check thegentlemen's published TTPs against your EDR coverage — the GentleKiller EDR-killer tooling means prevention assumptions need revisiting.

Incident timeline

DateEventStatus
2025-12 → 2026-07WaterPlum (Contagious Interview) campaign infects 30,000+ devices; $10.7M funneled to North KoreaDocumented in joint advisory (Sept 18)
Sept 24, 18:31 UTCBitget detects unauthorized transfers from hot/warm wallets; ~$351.6M drained, no private-key compromiseConfirmed by company; withdrawals frozen
Sept 25Elliptic assesses Bitget exploit "highly likely" DPRK-linked; tracked 2026 DPRK crypto theft passes $1BThreat-intel assessment
Sept 25, ~16:29 UTCEverest ransomware lists Securitas Group on leak siteClaim — unconfirmed
Sept 26, morningKeio Corporation detects ransomware on group servers; rail operations unaffectedConfirmed by company; investigating
Sept 26–27Storm lists Applied Composites and Magna Legal Services; thegentlemen lists Metalware Corp (Montreal); Arcus, m3rx, Barracuda add listingsClaims — unconfirmed
OngoingBitget fixes vulnerability, engages Mandiant and SlowMist; attribution under investigationIn progress

Sources

  1. Crypto exchange Bitget says hackers stole $352m — Moneyweb (Bloomberg)
  2. Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026 — Elliptic
  3. Japan's Keio Corporation hit by confirmed ransomware attack — Undercode News
  4. Japan dismantles first North Korean laptop farm as US and allies detail wider scheme — SecurityWeek
  5. Everest claims Securitas Group: leak-site claim, no breach confirmed — Undercode News
  6. Storm ransomware reportedly hits Applied Composites — Undercode News
  7. Metalware Corporation faces ransomware claim — Undercode News
Latest


EmoticonEmoticon