North Korean WaterPlum hackers infected 30,000 devices worldwide
AI Summary
North Korean threat actor WaterPlum conducted a global campaign from December 2025 to July 2026, compromising over 30,000 devices and stealing more than $10.7 million in cryptocurrency. The group targeted job seekers by impersonating legitimate companies and delivering malware through malicious npm packages and Visual Studio Code projects. WaterPlum deployed multiple malware families including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle to steal credentials, cryptocurrency keys, and conduct espionage. The actors are linked to North Korea's 313 General Bureau and operate alongside fraudulent IT worker operations using stolen identities and AI face-swapping during fake interviews.
AI-extracted · verify before operational use