North Korean WaterPlum hackers infected 30,000 devices worldwide

Refract AI Intelligence Digest

BLUF

North Korean state-sponsored actors successfully exfiltrated millions in crypto via a massive device compromise campaign spanning seven months.

NEWS

The WaterPlum group compromised at least 30,000 devices worldwide from December 2025 to July 2026, according to a joint law enforcement advisory. The attackers transferred more than $10.7 million in stolen cryptocurrency back to North Korea during this period.

Why I Care

This attack demonstrates the scale of financial theft possible through widespread device infection, directly funding adversarial regimes while compromising individual and corporate security. Organizations handling cryptocurrency or sensitive data face elevated risks of similar intrusion techniques being deployed against them.

Next Steps

Security teams should immediately review logs for indicators of compromise associated with WaterPlum activities and update endpoint protection signatures by the end of this week. Cryptocurrency holders and exchanges must enforce multi-factor authentication and monitor withdrawal patterns for anomalies starting now.

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.