North Korean Attackers Hit 30,000 Devices and Steal $10.7m
North Korea's WaterPlum infected about 30,000 devices and stole roughly $10.7 million in cryptocurrency.
A joint advisory from Japan's NPA, the FBI, Australia's ACSC, and German services says WaterPlum, also known as Contagious Interview, infected at least 30,000 devices in more than 100 countries between about December 2025 and July 2026. Actors posed as employers and delivered BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle through malicious NPM packages and Visual Studio Code projects, stealing credentials and wallet keys from over 7,000 cryptocurrency wallets. At least JPY 1.7 billion ($10.7 million) was transferred to North Korea. Agencies link some activity to North Korean IT workers under the 313 General Bureau and say Japan dismantled a laptop farm.