WaterPlum, a North Korean hacking group, compromised at least 30,000 devices in more than 100 countries and sent over $10.7 million in stolen cryptocurrency to North Korea. The campaign used fake interviews, malicious coding tests, and recruiter impersonation to spread malware and steal credentials, wallet data, and identity documents. #WaterPlum #ContagiousInterview #BeaverTail #InvisibleFerret #OtterCookie #OtterCandy #StoatWaffle #DPRK
Keypoints
- WaterPlum infected at least 30,000 devices worldwide from December 2025 through July 2026.
- The group stole more than $10.7 million in cryptocurrency and credentials from over 7,000 wallets.
- Attackers used fake AI, crypto, and NFT job postings to lure victims into the Contagious Interview campaign.
- The advisory links WaterPlum to several malware families, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
- Authorities say the activity supports North Koreaβs revenue generation and weapons programs.