North Korean Hackers Infiltrate 30,000 Devices in Global Crypto Scam
North Korea-linked hackers infected over 30,000 devices across more than 100 countries and regions between December 2025 and July 2026 in a massive crypto scam.
The hackers used a campaign called WaterPlum to target software developers, engineers, and Web3 workers through social media, recruitment websites, and freelance platforms. They impersonated legitimate AI, crypto, NFT, and recruitment companies while offering employment opportunities.
During the tasks, WaterPlum instructed candidates to download programs from collaborative development platforms and code repositories, which contained malicious NPM packages with malware families like BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. These supported remote access, credential theft, and data extraction.
The stolen information included browser credentials, clipboard contents, screenshots, keystrokes, private keys, and wallet seed phrases. Attackers also targeted driver's licenses, passports, and other identity documents.