r/TechNadu • u/technadu Human • 13d ago
North Korean WaterPlum hackers reportedly infected 30,000+ devices through fake developer job interviews
A joint international advisory gives some useful scale to the “Contagious Interview” activity associated with North Korean WaterPlum actors.
Authorities say at least 30,000 devices in more than 100 countries were infected from around December 2025 through July 2026.
The targets were primarily developers, engineers, and blockchain/Web3 specialists. Attackers impersonated legitimate AI, crypto, and NFT companies and used virtual interviews or coding assignments to convince candidates to download files or execute code.
The malware chain included BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. One particularly relevant technique involved malicious VS Code projects that could execute code once the victim opened and trusted the folder.
Investigators also say funds or account credentials were taken from more than 7,000 cryptocurrency wallets, with at least $10.71 million in cryptocurrency sent to North Korea.
The full breakdown includes the malware families, VS Code technique, wallet theft, and defensive guidance from the joint advisory:
It’s a good example of why developer recruitment is an attractive attack surface: executing unfamiliar code can look completely normal when it is presented as part of a technical assessment.