North Korea-Linked Hackers Infect 30,000 Devices, Steal $10.7M in Crypto
A sophisticated hacking operation linked to North Korea has compromised over 30,000 devices in more than 100 countries and stolen $10.71 million in cryptocurrency. The campaign, known as WaterPlum or Contagious Interview, targeted developers and IT professionals through fake recruitment campaigns on social networks, job platforms, and freelance marketplaces.
The attackers posed as recruiters or prospective employers from legitimate companies in the cryptocurrency, artificial intelligence, and NFT sectors. They would invite targets to technical interviews or coding assessments, which often involved downloading and executing malicious files. These payloads included malware like BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle.
Once installed, the malware could capture browser credentials, clipboard contents, keystrokes, and screenshots while searching for cryptocurrency private keys and seed phrases. The attackers also used remote-access tools to preserve access to infected machines and gain entry into networks belonging to the victim's employer or clients.