WaterPlum: North Korea-linked group hits 30,000 devices, transfers $10.7M in crypto

A joint law-enforcement advisory says the North Korean group WaterPlum compromised at least 30,000 devices in 100+ countries from Dec 2025 to July 2026, siphoning more than $10.7 million in cryptocurrency to DPRK. Linked to the Contagious Interview operation, WaterPlum used fake AI/crypto job interviews and malicious npm packages to infect targets, stealing wallet data, credentials, and other information, and sometimes pivoting into victims' networks. Malware families linked to WaterPlum include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Investigators note some actors also work as remote IT staff and reuse identities, including AI face-swapping during interviews. Authorities urge rigorous applicant verification and sandboxed code analysis to mitigate risk.
- North Korean WaterPlum hackers infected 30,000 devices worldwide BleepingComputer
- North Korean hackers behind crypto thefts across 100 countries, including Japan The Japan Times
- North Korea's fake job interviews infected 30,000 devices The Register
- Hackers Infect 30,000 Devices, Drain $11 Million From Crypto Wallets Yahoo
- FBI and Japanese Police Warn of North Korea-Linked WaterPlum Hackers Targeting IT Developers Binance
Want the full story? Read the original reporting
Read on BleepingComputer