North Korean Hackers Infect 30,000 Devices in Global Cyberespionage Campaign
North Korean threat actors, tracked as WaterPlum (also known as Contagious Interview), have compromised at least 30,000 devices across over 100 countries by exploiting job recruitment schemes targeting software developers, IT professionals, and cryptocurrency specialists. The campaign, active in recent months, has resulted in the theft of $10.71 million (JPY 1.7 billion) from over 7,000 cryptocurrency wallets, according to reports from the IC3 (Internet Crime Complaint Center).
Attack Methodology
WaterPlum operators engage victims through social media, job portals, freelance platforms, and recruitment services, posing as legitimate AI, blockchain, or NFT companies. The attackers lure targets with fake job interviews, often requesting coding assignments or troubleshooting tasks under the guise of technical evaluations.
Malicious files disguised as necessary tools for development or video conferencing are hosted on code repositories and collaboration platforms, making them appear credible to tech-savvy victims. In some cases, attackers used AI face-swapping software during interviews, later disabling video feeds to avoid detection.
Malware Arsenal
The campaign deploys multiple malware strains, including:
- BeaverTail – JavaScript-based malware hidden in npm packages.
- InvisibleFerret – A Python backdoor for remote access.
- OtterCookie – A remote access Trojan (RAT) and infostealer that exfiltrates sensitive data.
- StoatWaffle – Malicious Visual Studio Code projects that execute code via configuration files (e.g.,
.vscode/tasks.json).
Once installed, the malware harvests browser credentials, cryptocurrency wallet keys, seed phrases, screenshots, keystrokes, and sensitive files, enabling further compromise of victims’ employers, clients, or projects.
Broader Implications
Authorities link WaterPlum to DPRK IT-worker schemes, where North Korean operatives use laptop farms and virtual private servers (VPS) to obscure their locations, secure overseas contracts, and launder illicit earnings. Japanese investigators found overlapping IP addresses between WaterPlum and suspected North Korean IT workers accessing crowdsourcing platforms.
The stolen credentials and access tokens pose risks of corporate espionage, intellectual property theft, lateral movement within networks, and extortion. Security experts warn that compromised developers could inadvertently grant attackers access to enterprise systems, customer data, and ongoing projects.
Source: https://gbhackers.com/north-korean-waterplum-hackers-target-it-professionals/
IC3 TPRM report: https://www.rankiteo.com/company/ic3
"id": "ic31789813437",
"linkid": "ic3",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': ['Technology',
'Cryptocurrency',
'Blockchain',
'AI/NFT'],
'location': '100+ countries',
'type': 'Individuals (Software Developers, IT '
'Professionals, Cryptocurrency Specialists)'},
{'type': 'Enterprises (Potential Secondary Targets via '
'Compromised Developers)'}],
'attack_vector': ['Social Engineering',
'Fake Job Interviews',
'Malicious npm Packages',
'Malicious Visual Studio Code Projects'],
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'Yes (Browser '
'Credentials, '
'Cryptocurrency Wallet '
'Access)',
'sensitivity_of_data': 'High (Personally Identifiable '
'Information, Financial Data, '
'Intellectual Property)',
'type_of_data_compromised': ['Browser Credentials',
'Cryptocurrency Wallet Keys',
'Seed Phrases',
'Screenshots',
'Keystrokes',
'Sensitive Files']},
'description': 'North Korean threat actors, tracked as WaterPlum (also known '
'as Contagious Interview), have compromised at least 30,000 '
'devices across over 100 countries by exploiting job '
'recruitment schemes targeting software developers, IT '
'professionals, and cryptocurrency specialists. The campaign '
'has resulted in the theft of $10.71 million (JPY 1.7 billion) '
'from over 7,000 cryptocurrency wallets.',
'impact': {'data_compromised': ['Browser Credentials',
'Cryptocurrency Wallet Keys',
'Seed Phrases',
'Screenshots',
'Keystrokes',
'Sensitive Files'],
'financial_loss': '$10.71 million (JPY 1.7 billion)',
'identity_theft_risk': 'High (Personally Identifiable Information, '
'Cryptocurrency Wallet Access)',
'operational_impact': 'Risk of Corporate Espionage, Lateral '
'Movement in Networks, Extortion',
'payment_information_risk': 'High (Cryptocurrency Wallet '
'Compromise)',
'systems_affected': '30,000+ devices across 100+ countries'},
'initial_access_broker': {'backdoors_established': 'Yes (InvisibleFerret, '
'OtterCookie)',
'entry_point': ['Social Media',
'Job Portals',
'Freelance Platforms',
'Recruitment Services'],
'high_value_targets': ['Software Developers',
'IT Professionals',
'Cryptocurrency '
'Specialists']},
'investigation_status': 'Ongoing',
'motivation': ['Financial Gain', 'Espionage', 'Intellectual Property Theft'],
'post_incident_analysis': {'root_causes': ['Social Engineering via Fake Job '
'Interviews',
'Malicious npm Packages',
'Malicious Visual Studio Code '
'Projects',
'Lack of Verification in '
'Recruitment Processes']},
'references': [{'source': 'IC3 (Internet Crime Complaint Center)'}],
'response': {'law_enforcement_notified': 'IC3 (Internet Crime Complaint '
'Center)'},
'threat_actor': 'WaterPlum (Contagious Interview, Linked to North Korea/DPRK)',
'title': 'North Korean Hackers Infect 30,000 Devices in Global Cyberespionage '
'Campaign',
'type': 'Cyberespionage, Cryptocurrency Theft, Malware Deployment',
'vulnerability_exploited': 'Human Trust in Job Recruitment Schemes, Supply '
'Chain Compromise (npm Packages)'}