North Korean WaterPlum hackers infected 30,000 devices worldwide
ID: d8f10086-d188-5188-8625-46fd5092ad68
STIX ID: report--d8f10086-d188-5188-8625-46fd5092ad68
Feed Name: Bleeping Computer
A joint advisory from Japanese, U.S., Australian and German authorities attributes a multi-year North Korea-linked campaign called "Contagious Interview" to the WaterPlum group, which used malicious npm packages, fake job interviews, AI face‑swapping, and malicious Visual Studio Code projects to infect at least 30,000 devices across 100+ countries, steal credentials and cryptocurrency from over 7,000 wallets, and transfer roughly ¥1.7 billion (≈$10.71M) to DPRK; linked malware includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, and investigators link some operators to the DPRK 313 General Bureau and fraudulent IT-worker operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
