logo

North Korean WaterPlum hackers infected 30,000 devices worldwide

ID: d8f10086-d188-5188-8625-46fd5092ad68

STIX ID: report--d8f10086-d188-5188-8625-46fd5092ad68

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: Bill Toulas

...
...

A joint advisory from Japanese, U.S., Australian and German authorities attributes a multi-year North Korea-linked campaign called "Contagious Interview" to the WaterPlum group, which used malicious npm packages, fake job interviews, AI face‑swapping, and malicious Visual Studio Code projects to infect at least 30,000 devices across 100+ countries, steal credentials and cryptocurrency from over 7,000 wallets, and transfer roughly ¥1.7 billion (≈$10.71M) to DPRK; linked malware includes BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, and investigators link some operators to the DPRK 313 General Bureau and fraudulent IT-worker operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.