WaterPlum infects 30,000 devices, steals data from 7,000 crypto wallets

1 hour ago 2



A North Korean hacking operation known as WaterPlum compromised more than 30,000 devices worldwide and extracted data from over 7,000 cryptocurrency wallets, funneling at least 1.7 billion Japanese yen, roughly $10.71 million, into wallets tied to Pyongyang’s interests. The campaign, which ran from December 2025 through July 2026, targeted a specific demographic: IT professionals and software developers. The attackers posed as recruiters offering jobs at companies in AI, cryptocurrency, and NFTs. How the operation worked WaterPlum, also tracked under the name Contagious Interview, exploited something every developer does: apply for jobs. The hackers created fake recruiter profiles on social media and employment platforms, then invited targets to participate in fraudulent job interviews or complete coding tasks that were laced with malware. Once a victim engaged, a suite of custom malware did the heavy lifting. The toolbox included strains called BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. The programs were designed to extract sensitive data, with a particular focus on crypto wallet credentials and private keys. On September 18, 2026, a coalition of law en...

Read Entire Article