Signal Technology, daily
Last updated 21 September 2026 Türkçe
← All stories
Security

WaterPlum malware campaign hits 30,000 devices via fake dev job interviews

North Korea-linked operators are using fraudulent developer hiring to steal crypto and infiltrate employers’ networks.

Updated 21 September 2026

A new joint advisory from Japan, the U.S., Australia, and Germany says North Korea’s WaterPlum group has infected over 30,000 devices in more than 100 countries since December 2025, compromising 7,000+ crypto wallets and routing about $10.7 million in cryptocurrency to the DPRK. The campaign targets software developers and IT workers through fake job postings and interviews, where coding tests, npm packages, and Visual Studio Code projects hide malware such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Once installed, these tools steal browser credentials, clipboard contents, keystrokes, crypto keys, and documents, and can persist as RATs that remain on the developer’s machine for months. Authorities say WaterPlum overlaps with North Korea’s fraudulent IT worker operations under the 313 General Bureau, with some operators simultaneously working as remote IT staff and reusing IDs stolen in attacks to obtain jobs. The advisory urges companies to rigorously verify remote applicants and tightly scope access, and recommends developers run all interview code in sandboxes or isolated VMs and inspect files carefully for secondary payloads.

Why it matters

The campaign turns routine developer hiring into an attack surface. By hijacking job interviews and coding tests, WaterPlum steals browser data, documents, and crypto keys from individual applicants while also gaining footholds it can use to move into employers’ and clients’ networks for IP theft and espionage, all while channeling millions in cryptocurrency to help fund North Korea’s weapons programs.

Sources