An international advisory from Australian, German, Japanese, and US agencies says the North Korea-linked WaterPlum campaign has infected more than 30,000 devices, compromised over 7,000 cryptocurrency wallets, and stolen at least $10.71 million. Operators posing as recruiters target engineers, web designers, and cryptocurrency/Web3 professionals with fraudulent interviews and coding assignments that deploy backdoors, remote-access trojans, and information stealers. Stolen credentials and identity data can support cryptocurrency theft, espionage, extortion, corporate intrusion, and fraudulent North Korean IT-worker activity.
SentinelOne separately found DPRK-aligned TraderTraitor expanding the same job-lure tradecraft beyond cryptocurrency targets, compromising an Indian IT services provider through a weaponized Terraform repository. A typosquatted provider registry referenced in .terraform.lock.hcl enabled malicious modules to execute when a DevOps engineer ran Terraform; the engineer's Apple Silicon MacBook was subsequently infected with the FLATROOF and ROOFDECK macOS backdoors. The implants enabled credential theft, persistent remote command execution, reconnaissance, file transfer, and lateral movement, underscoring that developer endpoints with cloud, source-control, and CI/CD access are high-value targets regardless of their employer's industry.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
Collected telemetry recorded the final observed beacon from the loginwindow ROOFDECK variant to grenight.com.
The attackers staged a stripped ROOFDECK variant named loginwindow from 85.137.56.10 and installed it under ~/Library/com.apple.appleaccountd/loginwindow. They then used the new implant to remove the original FLATROOF and ROOFDECK binaries.
A TraderTraitor intrusion of LayerZero used a fake cryptocurrency minting event and a DDoS attack against validation servers, leading compromised servers to approve an illegitimate mint. The incident facilitated the theft of USD 292 million from KelpDAO.
After the victim opened the ~/DevOps-Automation/cloudshield workspace, Cursor launched the FLATROOF and ROOFDECK implants. The backdoors began beaconing and conducting host activity on the DevOps engineer's MacBook.
The Apple Silicon MacBook of a DevOps engineer at an India-based IT services provider contained the FLATROOF and ROOFDECK macOS backdoors by this date. The provider had no cryptocurrency affiliation, though the engineer had cloud credentials and source-control access.
Windows Security logs recorded a successful RDP session from 37.19.200.137, an IP associated with the DataCamp/CDNEXT-DAL commercial VPN/proxy network. Investigators attributed the session to the operator based on surrounding artifacts and prior infrastructure patterns.
Investigators entered rescue mode on a MonoVM-hosted Windows Server VPS, reviewed logs, and changed the local Administrator password. Later that day, they initiated an rsync collection of 69 GB from the mounted NTFS partition.
A Lazarus-linked operator imported two seed phrases into the Rabby Wallet extension on the examined VPS, consistent with wallet-drain activity.
Contagious Interview operators attempted to access Validin using excellentreporter321@gmail.com and marvel714jm@gmail.com after account restrictions were imposed.
The actors continued attempting to register accounts with Validin despite earlier blocking measures.
Contagious Interview operators attempted additional Validin registrations using the info@versusx.us, mvsolution9@gmail.com, and invite@quiz-nest.com identities.
Validin blocked the initially observed Contagious Interview accounts about 15 minutes after their first registrations and later restricted sign-ups using known Astrill VPN IP addresses and Gmail accounts.
North Korean-aligned Contagious Interview operators registered multiple Validin accounts using known campaign-linked Gmail addresses and Astrill VPN infrastructure. Their first observed search, for “TalentCheck,” occurred shortly afterward and reflected monitoring of published campaign indicators.
Validin published a blog post identifying Lazarus infrastructure associated with the Contagious Interview campaign, creating indicators that the operators subsequently monitored.
Australian, German, Japanese, and U.S. agencies issued an advisory on the North Korea-linked WaterPlum recruiter-impersonation campaign. They reported more than 30,000 compromised devices, more than 7,000 compromised cryptocurrency wallets, and at least USD 10.71 million stolen.
Lazarus used a fake Meta recruiter on LinkedIn to send Quiz1.iso and Quiz2.iso coding challenges to an aerospace company in Spain. Execution led to DLL side-loading and delivery of NickelLoader, miniBlindingCan, and the previously undocumented LightlessCan backdoor for espionage.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 62 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesentinelone.com
Open sourcetheregister.com
Open sourceredasgard.com
Open sourcesentinelone.com
Open sourcenpa.go.jp
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.