North Korean ‘WaterPlum’ Campaign Infects 30,000 Devices Across 100 Countries, Steals Crypto from Job Seekers
What Happened — North Korean actors operating the “WaterPlum” campaign compromised at least 30,000 devices in 100 nations by posing as recruiters on social‑media, gig‑work, and freelance portals. Victims were tricked into downloading malicious files that installed infostealer and remote‑management tools, allowing theft of cryptocurrency‑wallet credentials and persistent access to the devices.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous third‑party risk monitoring and verifiable onboarding controls to prevent supply‑chain compromise.
- Demonstrates why organizations must maintain auditable evidence of device hygiene and credential‑management for all external hires.
- Underlines the importance of endpoint detection and response (EDR) logs as defensible proof of control effectiveness.
Who Is Affected – Technology firms hiring remote engineers, cryptocurrency companies, recruitment platforms, and any organization that onboards external talent.
Recommended Actions – Verify candidate identities before granting network access, enforce endpoint security baselines on all devices used for work, and map supply‑chain risk controls to your audit framework with continuous evidence collection. Source: The Record
Technical Notes – Attack vector: social‑engineering (phishing) via fake recruiter messages; malware families include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle; primary data stolen: cryptocurrency‑wallet credentials and personal identifiers. Source: same as above