North Korea's WaterPlum Campaign Infected 30,000 Devices, Stole Crypto via Fake Job Interviews
A North Korean cyber group known as WaterPlum, also called Contagious Interview, conducted a campaign between December 2025 and July 2026 that infected at least 30,000 devices across more than 100 countries. Government agencies from the United States, Australia, Germany, and Japan jointly disclosed that attackers targeted IT professionals by posing as recruiters on social media, job boards, and freelance platforms. Victims were tricked into executing malicious npm packages or VS Code projects disguised as coding interview tasks, which deployed malware families including BeaverTail, InvisibleFerret, OtterCookie, and StoatWaffle. The campaign resulted in credentials and assets being stolen from over 7,000 cryptocurrency wallets, with at least 1.7 billion JPY in cryptocurrency transferred to North Korea. In a separate but related vector, North Korean operatives also infiltrated companies as fake remote employees using forged resumes, VPNs, and AI-assisted identity tools.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in