North Korea-Linked WaterPlum Infects 30,000 Devices and Steals $10.7M in Crypto

Coinbase
fiverr



A North Korea-linked hacking operation infected at least 30,000 computers across more than 100 countries and compromised funds or credentials from over 7,000 cryptocurrency wallets through fake recruitment campaigns targeting developers and IT professionals.

Betfury

The campaign, tracked as WaterPlum and widely known as Contagious Interview, stole at least 1.7 billion Japanese yen, or $10.71 million, in cryptocurrency between December 2025 and July 2026. The joint September 18 advisory involved Japan’s National Police Agency and National Cybersecurity Office, the FBI, the U.S. Defense Department’s Cyber Crime Center, and agencies in Australia and Germany.

Fake Recruiters Target Crypto and AI Developers

WaterPlum operators pose as recruiters or prospective employers representing legitimate cryptocurrency, artificial intelligence and NFT companies. Targets are approached through social networks, job platforms, freelance marketplaces and recruitment services before being invited to technical interviews or coding assessments.

Candidates are then instructed to download and execute malicious files, often under the pretext of completing a coding task or fixing a video-conferencing problem. The payloads include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle, delivered through malicious NPM packages, code repositories and Visual Studio Code projects.

Once installed, the malware can capture browser credentials, clipboard contents, keystrokes and screenshots while searching for cryptocurrency private keys and seed phrases. Remote-access tools preserve access to infected machines and can provide a path into networks belonging to the victim’s employer or clients.

The attack pattern extends the fake crypto job interview campaigns that have increasingly targeted developers through coding assignments, fake meeting software and malicious repositories.

FBI and NPA Link WaterPlum to North Korean State Structure

The FBI and NPA assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, which sits under the Central Committee of North Korea’s Workers’ Party.

Investigators also found overlap between the hacking operation and North Korean IT-worker schemes. The same IP addresses were used to access laptop farms, crowdsourcing services and applications for positions at a Japanese cryptocurrency exchange.

Japan dismantled one such laptop farm after identifying computers remotely controlled by North Korean workers. Similar infiltration risks surfaced this year when MetaMask removed a North Korea-linked contractor after the developer had spent about a month contributing to its codebase.

Compromised Wallets Should Be Replaced

The joint advisory warns that removing detected malware does not guarantee that previously stored wallet information remains secure. Users who suspect a device was compromised are advised to disconnect it from the internet, create a new wallet on a separate clean device and move assets to new addresses with a newly generated recovery phrase.

Authorities also recommend a full operating-system reset on infected machines and advise developers to run unfamiliar code only inside isolated virtual machines or sandboxes.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*