WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks
1. Basic Information Original Title: North Korean "WaterPlum," commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe Source: National Police Agency, NCO, FBI, DC3, ASD's ACSC, BND, BfV Publication Date: 2026-09-18 Update Date: None Severity: Critical Basis for Severity: Government…
The North Korean cyber group known as WaterPlum, also called "Contagious Interview," has infected roughly 30,000 devices across over 100 countries since December 2025. They targeted IT professionals through fake interviews and coding tasks, distributing malware disguised as npm packages or VS Code projects. This malware, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, stole personal information, established persistent access via remote access tools (RATs), and allowed the group to compromise organizations employing or contracting with the affected victims.
The group used various tactics, such as fake resumes, VPNs, AI-powered impersonation, and laptop farms, to infiltrate corporations. Victims received seemingly legitimate job offers, technical interview invitations, or troubleshooting steps, while administrators noticed unapproved npm packages, execution from external repositories, unfamiliar VS Code workspaces, and unauthorized access to sensitive data.
The impact of these attacks included the theft of crypto wallets, browser credentials, identification documents, screenshots, keystrokes, and corporate data.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.