WaterPlum Campaign Exposes Thousands of Devices to North Korean Malware
A joint advisory from law enforcement and cybersecurity agencies in Australia, Germany, Japan, and the US has revealed that North Korea's WaterPlum campaign has compromised over 30,000 devices. The attackers used fake job interviews to infect computers with malware and steal sensitive information.
The scam targets web designers, engineers, and cryptocurrency specialists with bogus recruitment approaches. Victims are instructed to download files presented as coding assignments or other recruitment tests, which backdoor the applicants' computers and install malware.
Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang.