North Korean WaterPlum hackers infected 30,000 devices worldwide
Key Points:
- The North Korean hacking group WaterPlum compromised over 30,000 devices worldwide between December 2025 and July 2026, stealing more than $10.7 million in cryptocurrency, according to a joint advisory from Japanese, US, Australian, and German authorities.
- WaterPlum operates under a multi-year campaign called "Contagious Interview," targeting job seekers by impersonating legitimate AI, cryptocurrency, and NFT companies, using fake interviews to deploy malware through malicious npm packages and coding tests.
- The group uses various malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, to steal credentials, cryptocurrency keys, documents, and conduct espionage by pivoting into employers' or clients' networks.
- WaterPlum is linked to North Korea's 313 General Bureau, part of the Munitions Industry Department, and is connected to fraudulent IT worker operations that reuse stolen identities to obtain jobs and aid in funding North Korea's weapons programs.
- Authorities advise companies to verify job applicants' identities thoroughly, restrict data access, and caution developers against running unknown code outside secure environments to mitigate WaterPlum's tactics.