North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
ID: f8b4e39c-4dce-543e-8ddb-58a9240d640a
STIX ID: report--f8b4e39c-4dce-543e-8ddb-58a9240d640a
Feed Name: GBHackers
WaterPlum (aka Contagious Interview) is a DPRK-linked campaign that has infected tens of thousands of devices across 100+ countries by luring web developers and crypto professionals into fraudulent technical interviews that deliver malware via code repositories, npm packages, and malicious Visual Studio Code projects; operators have stolen credentials and cryptocurrency from thousands of wallets (reported ~7,000 wallets, ≈JPY 1.7 billion / $10.71M). The report details malware families used (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle), common TTPs (social engineering via recruitment platforms, repository-hosted payloads, AI face-swapping during interviews), and defensive recommendations including sandboxing unknown code, enforcing least privilege, and rotating credentials and wallets after compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
