The North Korean hacking operation WaterPlum compromised more than 30,000 devices worldwide and extracted data from over 7,000 cryptocurrency wallets, funneling at least 1.7 billion Japanese yen, approximately $10.71 million, into wallets tied to Pyongyang’s interests. The campaign, which ran from December 2025 through July 2026, targeted IT professionals and software developers, whom the attackers approached by posing as recruiters offering jobs in AI, cryptocurrency, and NFTs. The malware strains used included BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, designed to extract wallet credentials and private keys. On September 18, 2026, the US FBI and Japan’s National Police Agency formally attributed the campaign to the 313th Bureau of North Korea’s Munitions Industry Department.
Source: Read the original article

