WaterPlum Hackers Swipe $10 Million in Crypto from 30,000 Devices
The North Korean hacking operation known as WaterPlum compromised over 30,000 devices worldwide and extracted data from more than 7,000 cryptocurrency wallets. The campaign, which ran from December 2025 through July 2026, targeted IT professionals and software developers.
WaterPlum exploited the common practice of job seekers applying for positions on social media and employment platforms. The hackers created fake recruiter profiles that invited targets to participate in fraudulent interviews or complete coding tasks laced with malware.
The suite of custom malware used by WaterPlum included strains such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. These programs were designed to extract sensitive data, particularly crypto wallet credentials and private keys.