Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»North Korean WaterPlum hackers infected 30,000 devices worldwide
    News

    North Korean WaterPlum hackers infected 30,000 devices worldwide

    adminBy adminSeptember 19, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    North Korea

    A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.

    The figures came from a joint advisory by Japanese, US, Australian, and German authorities that collectively traced the threat group’s activity.

    WaterPlum is linked to a multi-year campaign known as “Contagious Interview,” which has previously targeted job seekers with malicious npm packages hat infect their devices with malware.

    The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.

    During fake interviews and coding tests, victims are instructed to download projects, troubleshoot supposed video-conferencing problems, or execute malicious code.

    Diagram
    Source: FBI

    WaterPlum is part of a broader ecosystem of North Korean threat actors that conduct financially motivated attacks to generate revenue for the regime and help fund its weapons programs.

    “WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,” reads the advisory.

    “WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People’s Republic of Korea (DPRK).”

    The advisory links several malware families to WaterPlum operations, including:

    1. BeaverTail: JavaScript malware concealed in npm packages.
    2. InvisibleFerret: Python-based backdoor.
    3. OtterCookie: JavaScript remote-access trojan and information stealer.
    4. OtterCandy: Malware combining OtterCookie and RAT capabilities.
    5. StoatWaffle: Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.

    Once a target is compromised, the attackers attempt to steal browser credentials, clipboard contents, keystrokes, cryptocurrency private keys and seed phrases, and documents, while also capturing screenshots.

    They may also use access to infected computers to pivot to their employers’ or clients’ networks, expanding the attacks to intellectual property theft and espionage.

    The agencies also directly connect WaterPlum to North Korea’s fraudulent IT worker operations, stating that some WaterPlum hackers also work as remote IT workers performing web development for clients and that the two groups have used the same IP addresses.

    The advisory also warns that North Korean IT workers then reuse identity documents stolen in WaterPlum attacks to impersonate victims and obtain jobs.

    Investigators also found that the WaterPlum actors use AI face-swapping software during online interviews, then turn off their cameras and blame network problems.

    FIB
    Source: FBI

    The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country’s 313 General Bureau, which is part of the Munitions Industry Department responsible for North Korea’s weapons research and production.

    Japan’s National Police Agency says authorities identified, investigated, and dismantled a North Korean IT-worker “laptop farm” in the country for the first time, finding evidence that several hundred million yen had been transferred abroad.

    The advisory warns companies to carefully verify job applicants’ identities, locations, and qualifications and restrict their access to only the systems and data required to perform their jobs.

    Developers should avoid running unknown code outside a sandbox and inspect provided files and code for commands that fetch additional payloads.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCanadian Security Intelligence Service Justification Framework (2024)
    Next Article ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
    admin
    • Website

    Related Posts

    News

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    News

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    News

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Viral AI actress’ hotline face-scans every caller, watches their mood

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.