INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korean WaterPlum Hackers Infect 30,000 Devices Worldwide

| 2026-09-29 05:25 CRITICAL MEDIUM STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The United States, Japan, Australia, Germany and the European Union have joined forces with North Korean authorities to combat a surge in cyberattacks targeting IT professionals and their employers. Malware families such as StoatWaffle6, BeaverTail, InvisibleFerret, Remote Access, OtterCandy, [IOC HIDDEN • LOGIN REQUIRED], Cyber Actor, WaterPlum have been identified, with the malicious actors using techniques including Firmware Corruption (T1495), Ingress Tool Transfer (T1105) and Resource Hijacking (T1496). The attacks targeted 30,000 devices worldwide, primarily in education and cryptocurrency sectors. North Korean hackers, known as Contagious Interview or WaterPlum, have been linked to a long-running hiring scheme that has compromised over 7,000 cryptocurrency wallets, with an estimated $10.71 million ultimately reaching the rogue nation.
Technical Mitigations AI-generated
• Implement robust security measures for cryptocurrency wallets, including multi-factor authentication and regular monitoring. • Conduct thorough vulnerability assessments on web applications to prevent exploitation of known vulnerabilities such as Netscaler RCE (Remote Access) and WAF bypass techniques used by WaterPlum hackers. • Utilize IP address blocking and logging mechanisms to detect and track suspicious activity from known WaterPlum actors, including those using the same IP addresses for malicious activities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

no•••••.js
No•••••.js
103.85.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview InvisibleFerretInvisibleFerretBeaverTailBeaverTail
Target & Sectors
DPRK DPRK DACH DACH NORTH_AMERICA NORTH_AMERICA NORDICS NORDICS cryptocurrencycryptocurrency governmentgovernment technologytechnology
Incident Timeline
‎May 2025
A Japanese cryptocurrency exchange rejected a suspicious applicant in May 2025, potentially preventing further malicious activity.
target_region Japan
‎Between December 2025
Threat actors using the WaterPlum malware infected at least 30,000 devices across more than 100 countries between December 2025 and July 2026.
infrastructure 30,000 devices
general_metric 100 countries
‎December 2025
Threat actors using the WaterPlum hacking group compromised at least 30,000 devices worldwide from December 2025 through July 2026.
source_region DPRK
target_region Korea, Democratic People's Republic of
infrastructure 30,000 devices
‎July 2026
Threat actors using WaterPlum, a North Korean hacking group, infected at least 30,000 devices worldwide between December 2025 and July 2026.
infrastructure 30,000 devices
general_metric 100 countries
source_region DPRK
target_region Korea, Democratic People's Republic of
‎2026/09/29
North Korean WaterPlum hackers infected 30,000 devices worldwide using malware and social engineering tactics.
organisation the European Union
organisation EU
threat_actor Contagious Interview
organisation the 313 General Bureau
organisation the Munitions Industry Department
organisation the Workers’ Party of Korea’s Central Committee
infrastructure 30,000 devices
organisation North Korean Laptop Farm
organisation IP
organisation Interviewers
organisation Remote Access
organisation Cyber Actor
organisation Visual Studio Code
organisation StoatWaffle
organisation OtterCandy
organisation the Democratic People's Republic of Korea
organisation NFT
organisation OtterCookie
organisation NFL
organisation CHANEL
Tactical Metrics
Metrics
infrastructure
30,000
Devices
Metrics
infrastructure
‎Visual Studio Code
Affected Product