INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
North Korean WaterPlum Hackers Infect 30,000 Devices Worldwide
| 2026-09-29 05:25 CRITICAL MEDIUM STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The United States, Japan, Australia, Germany and the European Union have joined forces with North Korean authorities to combat a surge in cyberattacks targeting IT professionals and their employers. Malware families such as StoatWaffle6, BeaverTail, InvisibleFerret, Remote Access, OtterCandy, [IOC HIDDEN • LOGIN REQUIRED], Cyber Actor, WaterPlum have been identified, with the malicious actors using techniques including Firmware Corruption (T1495), Ingress Tool Transfer (T1105) and Resource Hijacking (T1496). The attacks targeted 30,000 devices worldwide, primarily in education and cryptocurrency sectors. North Korean hackers, known as Contagious Interview or WaterPlum, have been linked to a long-running hiring scheme that has compromised over 7,000 cryptocurrency wallets, with an estimated $10.71 million ultimately reaching the rogue nation.
Technical Mitigations AI-generated
• Implement robust security measures for cryptocurrency wallets, including multi-factor authentication and regular monitoring.
• Conduct thorough vulnerability assessments on web applications to prevent exploitation of known vulnerabilities such as Netscaler RCE (Remote Access) and WAF bypass techniques used by WaterPlum hackers.
• Utilize IP address blocking and logging mechanisms to detect and track suspicious activity from known WaterPlum actors, including those using the same IP addresses for malicious activities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
no•••••.js
No•••••.js
103.85.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview
InvisibleFerretInvisibleFerretBeaverTailBeaverTail
Target & Sectors
DPRK
DPRK
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
NORDICS
NORDICS
cryptocurrencycryptocurrency
governmentgovernment
technologytechnology
Incident Timeline
May 2025
A Japanese cryptocurrency exchange rejected a suspicious applicant in May 2025, potentially preventing further malicious activity.
Click on any entity below to view its context and source!
target_region
Japan
Telltale signs that exposed operatives
The advisory describes a case from a Japanese cryptocurrency exchange that turned down a suspicious applicant in May 2025.
Between December 2025
Threat actors using the WaterPlum malware infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026.
Click on any entity below to view its context and source!
infrastructure
30,000 devices
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries.
general_metric
100 countries
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries.
December 2025
Threat actors using the WaterPlum hacking group compromised at least 30,000 devices worldwide from December 2025 through July 2026.
Click on any entity below to view its context and source!
source_region
DPRK
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
target_region
Korea, Democratic People's Republic of
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
infrastructure
30,000 devices
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
July 2026
Threat actors using WaterPlum, a North Korean hacking group, infected at least 30,000 devices worldwide between December 2025 and July 2026.
Click on any entity below to view its context and source!
infrastructure
30,000 devices
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries.
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
general_metric
100 countries
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries.
source_region
DPRK
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
target_region
Korea, Democratic People's Republic of
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
2026/09/29
North Korean WaterPlum hackers infected 30,000 devices worldwide using malware and social engineering tactics.
Click on any entity below to view its context and source!
organisation
the European Union
The United States, Japan, Australia, Germany and the European Union (EU) are working with North Korean authorities to combat cyberattacks targeting IT professionals and their employers.
organisation
EU
The United States, Japan, Australia, Germany and the European Union (EU) are working with North Korean authorities to combat cyberattacks targeting IT professionals and their employers.
threat_actor
Contagious Interview
Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as
Contagious Interview
.
WaterPlum is linked to a multi-year campaign known as "Contagious Interview," which has previously
targeted job seekers
with
malicious npm packages
hat infect their devices with malware.
organisation
the 313 General Bureau
The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee.
organisation
the Munitions Industry Department
The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee.
organisation
the Workers’ Party of Korea’s Central Committee
The National Police Agency of Japan and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the same part of the regime: the 313 General Bureau of the Munitions Industry Department, under the Workers’ Party of Korea’s Central Committee.
infrastructure
30,000 devices
North Korean WaterPlum hackers infected 30,000 devices worldwide.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,"
reads the advisory
.
organisation
North Korean Laptop Farm
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme.
organisation
IP
The advisory also states that WaterPlum actors and North Korean IT workers have been seen using the same IP addresses, including when accessing laptop farms and applying for jobs.
organisation
Interviewers
Interviewers who encountered other suspected North Korean IT workers reported similar patterns, including reluctance to meet in person, requests to be paid in cryptocurrency, and applicants who appeared to glance at a second screen as if reading answers.
organisation
Remote Access
Malware families: StoatWaffle6, BeaverTail, InvisibleFerret, Remote Access, OtterCandy, Node.js, Cyber Actor, WaterPlum
MITRE ATT&CK: T1495, T1562, T1105, T1496, T1027
Targeted countries: Korea, Democratic People's Republic of
organisation
Cyber Actor
Malware families: StoatWaffle6, BeaverTail, InvisibleFerret, Remote Access, OtterCandy, Node.js, Cyber Actor, WaterPlum
MITRE ATT&CK: T1495, T1562, T1105, T1496, T1027
Targeted countries: Korea, Democratic People's Republic of
organisation
Visual Studio Code
StoatWaffle:
Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
organisation
StoatWaffle
StoatWaffle:
Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
organisation
OtterCandy
OtterCandy:
Malware combining OtterCookie and RAT capabilities.
organisation
the Democratic People's Republic of Korea
"WaterPlum actors have transferred 1.7 billion Japanese yen (JPY) (equivalent to 10.71 million USD) of cryptocurrency assets to the Democratic People's Republic of Korea (DPRK).
organisation
NFT
WaterPlum campaign overview
WaterPlum
poses as employers to reach software developers and IT professionals, often impersonating real AI, cryptocurrency or NFT companies.
The attackers impersonate legitimate AI, cryptocurrency, and NFT companies or use recruiting and freelance platforms to approach job seekers.
organisation
OtterCookie
OtterCookie:
JavaScript remote-access trojan and information stealer.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Click for context!
North Korean WaterPlum hackers infected 30,000 devices worldwide.
Between December 2025 and July 2026, WaterPlum infected at least 30,000 devices across more than 100 countries.
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea.
"WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets,"
reads the advisory
.
Metrics
infrastructure
Visual Studio Code
Affected Product
StoatWaffle:
Modular Node.js malware delivered through malicious Visual Studio Code projects, using configuration files that execute code after a folder is opened and trusted.
Intelligence Sources
BleepingComputer
2026-09-19
North Korean WaterPlum hackers infected 30,000 devices worldwide
BleepingComputer
SecurityWeek
2026-09-22
AlienVault OTX
2026-09-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
the European Union
entity
8x
target region
Target Country
United States
country
8x
tactic
MITRE ATT&CK Technique
T1495 - Firmware Corruption
technique
6x
attribution
Attributing Entity
The National Police Agency
authority
4x
timeline
Temporal Reference
Between December 2025
date
3x
source region
Origin Country
Japan
country
3x
tactic
Cyber Operation Type
Extortion
tactic
2x
target region
Target Region
EUROPE
region
2x
malware
Malware Payload
BeaverTail
tool
2x
industry
Targeted Sector
Education
sector
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Region
DPRK
region
infrastructure
Devices
30,000
devices
threat actor
APT Group
Contagious Interview
actor
general metric
Cryptocurrency Wallets
7,000
cryptocurrency wallets
general metric
General Bureau
313
general bureau
general metric
Countries
100
countries
general metric
Japanese Yen
1,700,000,000
japanese yen
infrastructure
Affected Product
Visual Studio Code
software
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.