
WaterPlum: North Korea-linked group hits 30,000 devices, transfers $10.7M in crypto
A joint law-enforcement advisory says the North Korean group WaterPlum compromised at least 30,000 devices in 100+ countries from Dec 2025 to July 2026, siphoning more than $10.7 million in cryptocurrency to DPRK. Linked to the Contagious Interview operation, WaterPlum used fake AI/crypto job interviews and malicious npm packages to infect targets, stealing wallet data, credentials, and other information, and sometimes pivoting into victims' networks. Malware families linked to WaterPlum include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Investigators note some actors also work as remote IT staff and reuse identities, including AI face-swapping during interviews. Authorities urge rigorous applicant verification and sandboxed code analysis to mitigate risk.

