North Korean hacking group 'WaterPlum' targets IT professionals in large-scale campaign
A North Korean-linked hacking group known as 'WaterPlum' (also called Contagious Interview) is targeting IT job seekers with fake recruitment offers disguised as AI, crypto, and NFT companies. The group induces victims to download NPM packages containing malware such as BeaverTail, InvisibleFerret, and OtterCookie to steal crypto wallet data and confidential information. As of July 2026, the group has infected over 30,000 devices across 100 countries, stealing data from 7,000+ wallets and accumulating at least 1.7 billion JPY (approx. 10.71 million USD). Japanese police, in coordination with the FBI and other international agencies, have dismantled a 'laptop farm' operated by local supporters. The group is believed to be under the command of the 313 General Bureau of the Munitions Industry Department of the Workers' Party of Korea.
Summaries are written by AI from the original article. Not investment advice.