logo

North Korean WaterPlum Hackers Infect 30,000 Devices via Fake Job Interviews to Steal Crypto

ID: 708302a9-0afd-557c-a1ea-7848221a0577

STIX ID: report--708302a9-0afd-557c-a1ea-7848221a0577

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Divya

...
...

North Korean-linked actors called WaterPlum (Contagious Interview) conducted a global campaign (Dec 2025–Jul 2026) targeting developers, freelancers, and crypto professionals by posing as recruiters and delivering malicious npm packages and Visual Studio Code projects (malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle), compromising ~30,000 devices across 100+ countries and stealing funds from >7,000 cryptocurrency wallets (estimated JPY 1.7 billion / $10.71M); the advisory recommends avoiding execution of untrusted interview code, using isolated VMs/sandboxes, enforcing least privilege, reviewing npm/VSCode files, and using EDR to detect loaders and information stealers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.