WaterPlum Cyber Campaign Hacks 30K Devices, Steals 7K Crypto Wallet Records
A large-scale cyber campaign has been exposed by Japan's National Police Agency (NPA), targeting IT professionals and cryptocurrency theft. The operation, known as WaterPlum, hacked over 30,000 devices in more than 100 countries and accessed information from over 7,000 crypto wallets.
The attackers targeted web developers, designers, and crypto and blockchain experts through social media and job postings. They disguised themselves as trusted firms, conducting online interviews that included coding assignments and software problems to solve. Some applicants were given files to download, which could contain malware compromising their machines.
The NPA found multiple malware families associated with the attack, including OtterCandy, OtterCookie, InvisibleFerret, BeaverTail, and StoatWaffle. These malicious programs can grant persistent access to a system, extract sensitive information, and steal wallet credentials.
According to investigators, over $10.71 million in cryptocurrency was moved to wallets operated by WaterPlum. Japanese authorities also discovered a 'laptop farm' where computers were controlled remotely by North Koreans, used for accepting jobs and masking actual identities. The NPA and FBI concluded that the activities of WaterPlum and some North Korean IT workers were directed by the Munitions Industry Department's Bureau 313 of the Workers' Party of Korea.